CVE-2026-1560

HIGH

WordPress Lazy Blocks <4.2.0 - Authenticated RCE

Title source: llm

Description

The Custom Block Builder – Lazy Blocks plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.2.0 via multiple functions in the 'LazyBlocks_Blocks' class. This makes it possible for authenticated attackers, with Contributor-level access and above, to execute code on the server.

Exploits (2)

github WORKING POC 10 stars
by XiaomingX · pythonpoc
https://github.com/XiaomingX/data-cve-poc-py-v1/tree/main/2026/CVE-2026-1560
nomisec WORKING POC 1 stars
by Z3YR0xX · poc
https://github.com/Z3YR0xX/CVE-2026-1560-Authenticated-Remote-Code-Execution-in-Lazy-Blocks-4.2.0

Scores

CVSS v3 8.8
EPSS 0.0015
EPSS Percentile 35.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-94
Status published
Products (1)
nko/Custom Block Builder – Lazy Blocks < 4.2.0
Published Feb 11, 2026
Tracked Since Feb 18, 2026