CVE-2025-8059: Bplugins Bblocks – Essential Gutenberg Blocks & Patterns Collection

Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.

The B Blocks plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization and improper input validation within the rgfr_registration() function in all versions up to, and including, 2.0.6. This makes it possible for unauthenticated attackers to create a new account and assign it the administrator role.

Affected products

  • Bplugins Bblocks – Essential Gutenberg Blocks & Patterns Collection: up to and including 2.0.6

Published 2025-08-12. Last modified 2026-06-17.