---
id: CVE-2025-12449
title: >-
  The aBlocks – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to
  unauthorized modification of data and disclosure of sensitive information due
  to missing capability checks on multiple AJAX actions in all versions up to,
  and…
summary: >-
  The aBlocks – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to
  unauthorized modification of data and disclosure of sensitive information due
  to missing capability checks on multiple AJAX actions in all versions up to,
  and…
severity: medium
cvss: 5.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'
cwe:
  - CWE-862
vendor: kodezen
product: >-
  aBlocks – Gutenberg Blocks, User Dashboard Builder, Popup Builder, Form
  Builder & Animation Builder
affected:
  - >-
    ablocks_gutenberg_blocks_user_dashboard_builder_popup_builder_form_builder_animation_builder
    <= 2.4.0
published: '2026-01-07'
updated: '2026-09-15'
sourceUpdated: '2026-09-15T16:17:07.203'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-12449'
references:
  - url: >-
      https://plugins.trac.wordpress.org/browser/ablocks/tags/2.4.0/includes/ajax/settings.php#L16
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/ablocks/tags/2.4.0/includes/assets.php#L353
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/ablocks/tags/2.4.0/includes/classes/abstract-request-handler.php#L486
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/changeset?old_path=/ablocks/trunk/includes/classes/abstract-request-handler.php&old=3269886&new_path=/ablocks/trunk/includes/classes/abstract-request-handler.php&new=3401920
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/c10600ae-1ff0-4f12-ae53-39d9342640f4?source=cve
    label: security@wordfence.com
tags:
  - nvd
  - cve.org
epss: 0.0025
epssPercentile: 0.14498
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-01-07T14:50:05.893571Z'
ingestedAt: '2026-09-15T15:39:12.935Z'
---

## Overview

The aBlocks – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized modification of data and disclosure of sensitive information due to missing capability checks on multiple AJAX actions in all versions up to, and including, 2.4.0. This makes it possible for authenticated attackers, with subscriber level access and above, to read plugin settings including block visibility, maintenance mode configuration, and third-party email marketing API keys, as well as read sensitive configuration data including API keys for email marketing services.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
