CVE-2026-6703: Responsive Blocks <= 2.2.1 - Missing Authorization to Authenticated (Contributor+) Arbitrary Modification via AJAX Actions
The Responsive Blocks – Page Builder for Blocks & Patterns plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 2.2.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with contributor-level access and above, to modify global site-wide plugin configuration options, including toggling custom CSS, disabling blocks, changing layout defaults such as content width, container padding, and container gap, and altering auto-block-recovery behavior.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-6703?
CVE-2026-6703 is considered a high severity vulnerability due to the potential for unauthorized access and arbitrary modification by authenticated users.
How do I fix CVE-2026-6703?
To fix CVE-2026-6703, upgrade the Responsive Blocks – Page Builder for Blocks & Patterns plugin to version 2.2.2 or later.
Who is affected by CVE-2026-6703?
All users of the Responsive Blocks – Page Builder for Blocks & Patterns plugin up to and including version 2.2.1 are affected by CVE-2026-6703.
What is the nature of the vulnerability described in CVE-2026-6703?
CVE-2026-6703 involves a missing authorization check that allows authenticated users with Contributor+ roles to perform arbitrary modifications via AJAX actions.
When was CVE-2026-6703 published?
CVE-2026-6703 was published in 2026, highlighting the security issue in versions of the plugin prior to 2.2.2.