CVE-2026-88994: All Bootstrap Blocks 1.3.20 - 1.3.31 - Contributor+ LFI via lightspeed Block Attributes

Published Sep 18, 2026
·
Updated

The All Bootstrap Blocks WordPress plugin through 1.3.31 does not validate a block attribute before using it to build a filesystem path that is included at render time, allowing users with contributor-level access and above to include arbitrary local files, disclose their contents, and execute PHP where a local file containing PHP code can be reached. Exploitation requires the plugin's Lightspeed subsystem to be enabled, which is not the default.

Affected Software

1 affected component
WordPress All Bootstrap Blocks>=1.3.20<=1.3.31

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade All Bootstrap Blocks (WordPress plugin) to a version that resolves this vulnerability.

    Fixed in 1.3.31
  2. Configuration

    Disable the plugin's Lightspeed subsystem (exploitation requires it to be enabled; it is not enabled by default).

    All Bootstrap Blocks (WordPress plugin) - Lightspeed subsystem Lightspeed subsystem enabled = false

Event History

Sep 18, 2026
CVE Published
via MITRE·06:11 AM
Data Sourced
via MITRE·06:11 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which sites are exposed to exploitation?

Sites using All Bootstrap Blocks through version 1.3.31 are exposed only if the plugin's Lightspeed subsystem is enabled. Lightspeed is not enabled by default.

2

What access does an attacker need?

An attacker needs a WordPress account with Contributor-level permissions or higher. No user interaction is required once the attacker has the necessary access.

3

What could exploitation allow?

An attacker may include arbitrary local files, disclose their contents, and execute PHP if they can reach a local file containing PHP code.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203