Skip to main content
Vulnerability Database/CVE-2026-88994

CVE-2026-88994: All Bootstrap Blocks Path Traversal Flaw

CVE-2026-88994 is a path traversal vulnerability in All Bootstrap Blocks WordPress plugin allowing contributors to include arbitrary files and execute PHP code. This post covers technical details, affected versions, exploitation requirements, and mitigation steps.

Published:

CVE-2026-88994 Overview

CVE-2026-88994 affects the All Bootstrap Blocks WordPress plugin through version 1.3.31. The plugin fails to validate a block attribute before using it to construct a filesystem path included at render time. Authenticated users with contributor-level access or higher can include arbitrary local files, disclose their contents, and execute PHP when a reachable local file contains PHP code. Exploitation requires the plugin's Lightspeed subsystem to be enabled, which is not the default configuration. The weakness is classified under [CWE-98] as improper control of filename for include/require statement in a PHP program.

Critical Impact

Authenticated contributors can read arbitrary local files and execute PHP code on the WordPress host when a suitable file is reachable and the Lightspeed subsystem is enabled.

Affected Products

  • All Bootstrap Blocks WordPress plugin versions through 1.3.31
  • WordPress installations with the plugin's Lightspeed subsystem enabled
  • Sites permitting contributor-level or higher user registration

Discovery Timeline

  • 2026-09-18 - CVE-2026-88994 published to NVD
  • 2026-09-18 - Last updated in NVD database

Technical Details for CVE-2026-88994

Vulnerability Analysis

The vulnerability resides in the All Bootstrap Blocks plugin's block rendering logic. The plugin accepts a user-controlled block attribute and passes it into a PHP file include operation without validating the value against an allowlist or normalizing traversal sequences. When the Lightspeed subsystem processes the block at render time, the attacker-controlled path is resolved on the local filesystem. Any file the web server user can read becomes accessible through the include operation. If the included file contains PHP code, the interpreter executes it in the WordPress process context.

Root Cause

The root cause is missing input validation on a block attribute later used to build a filesystem path for a PHP include or require statement. The plugin trusts the attribute value supplied by the block editor without confirming the resolved path stays within an expected template directory. This pattern maps directly to [CWE-98], PHP Remote File Inclusion, and its local file inclusion variant.

Attack Vector

An authenticated user with contributor-level access authors a post or block containing the vulnerable Bootstrap block. The attacker sets the malicious attribute to a filesystem path targeting a sensitive file such as wp-config.php, session files, log files, or an uploaded PHP payload. When the block renders, the plugin includes the referenced file. Sensitive contents return in the rendered output, and PHP within the file executes. Exploitation is gated by the non-default Lightspeed subsystem being enabled, which reduces the practical exposure.

No verified proof-of-concept code is publicly available. See the WPScan Vulnerability Report for further technical detail.

Detection Methods for CVE-2026-88994

Indicators of Compromise

  • Unexpected block attributes containing filesystem paths, traversal sequences such as ../, or references to files outside the plugin's template directories.
  • Web server access logs showing contributor-authored post renders that return contents of wp-config.php, /etc/passwd, or other sensitive files.
  • New or modified PHP files under wp-content/uploads/ that later appear referenced by Bootstrap block attributes.
  • PHP error log entries referencing include or require on unusual absolute paths originating from the All Bootstrap Blocks plugin.

Detection Strategies

  • Audit the WordPress database wp_posts table for post_content containing All Bootstrap Blocks markup with suspicious path-like attribute values.
  • Inspect file integrity of the plugin directory and compare against the vendor-distributed version 1.3.31 or earlier baseline.
  • Correlate contributor account activity with post-render events that produce abnormally large or sensitive-looking response bodies.

Monitoring Recommendations

  • Log and alert on newly created contributor and author accounts, especially on sites permitting open registration.
  • Monitor PHP open_basedir violations and file access anomalies on the WordPress host.
  • Track configuration changes that enable the plugin's Lightspeed subsystem, since the vulnerability requires it to be active.

How to Mitigate CVE-2026-88994

Immediate Actions Required

  • Disable the All Bootstrap Blocks plugin's Lightspeed subsystem if it is not required, since exploitation depends on it.
  • Restrict contributor-level and higher accounts to trusted users and review recent role assignments.
  • Deactivate the plugin on production sites until a fixed version is installed and validated.

Patch Information

At the time of publication, the WPScan advisory lists all versions through 1.3.31 as vulnerable. Administrators should consult the WPScan Vulnerability Report and the plugin vendor's changelog for the fixed release, then upgrade to a version later than 1.3.31 once available.

Workarounds

  • Keep the Lightspeed subsystem disabled, which is the default state and blocks the exploitation path.
  • Enforce least privilege by removing unnecessary contributor accounts and requiring editor review before publishing.
  • Apply a web application firewall rule that inspects block attributes for filesystem path characters and traversal sequences.
  • Configure PHP open_basedir and disable_functions to constrain file inclusion scope and limit post-exploitation impact.
bash
# Configuration example: restrict PHP file access scope for WordPress
# In php.ini or a pool configuration for the WordPress site
open_basedir = "/var/www/wordpress/:/tmp/"

# Optional: enforce read-only permissions on plugin directory
chown -R root:www-data /var/www/wordpress/wp-content/plugins/all-bootstrap-blocks
find /var/www/wordpress/wp-content/plugins/all-bootstrap-blocks -type f -exec chmod 0644 {} \;
find /var/www/wordpress/wp-content/plugins/all-bootstrap-blocks -type d -exec chmod 0755 {} \;

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.