
CVE-2026-3454 The GenerateBlocks plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.2.0. This is due to missing object-lev… https://www.cve.org/CVERecord?id=CVE-2026-3454
Post summary
This post announces that the GenerateBlocks WordPress plugin up to v2.2.0 is vulnerable to an Insecure Direct Object Reference, but provides no PoC, exploit, or patch information.


