CVE-2025-8059 Details
Description
The B Blocks plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization and improper input validation within the rgfr_registration() function in all versions up to, and including, 2.0.6. This makes it possible for unauthenticated attackers to create a new account and assign it the administrator role.
A privilege escalation vulnerability has been identified in the B Blocks plugin for WordPress, affecting all versions through 2.0.6. The issue arises from missing authorization and inadequate input validation in the rgfr_registration() function, allowing unauthenticated attackers to create accounts with administrator privileges.
Users are advised to update the B Blocks plugin to version 2.0.7 or later, where this vulnerability has been patched.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Aug 12, 2025CISA-ADP
Assessed Aug 12, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://plugins.trac.wordpress.org/browser/b-blocks/trunk/includes/blocks/RegisterForm.php#L77 | [email protected] | Broken LinkSource CodeVendor |
| https://plugins.trac.wordpress.org/changeset/3340770/ | [email protected] | Source CodeVendor |
| https://wordpress.org/plugins/b-blocks/#developers | [email protected] | ProductVendor |
| https://www.wordfence.com/threat-intel/vulnerabilities/id/0ee3b389-60c9-4f8e-9428-a71a6d9b20aa?source=cve | [email protected] | AdvisoryRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-862 | Missing Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| bPlugins B Blocks | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Aug 12, 2025 | New CVE Received | [email protected] |
Volerion