Feed/CVE-2026-6675
CVE-2026-6675MEDIUMCVSS 5.3

CVE-2026-6675

Published Apr 20, 2026·Updated Jun 17, 2026

NVD Description

The Responsive Blocks – Page Builder for Blocks & Patterns plugin for WordPress is vulnerable to Unauthenticated Open Email Relay in all versions up to, and including, 2.2.0. This is due to insufficient authorization checks and missing server-side validation of the recipient email address supplied via a public REST API route. This makes it possible for unauthenticated attackers to send arbitrary emails to any recipient of their choosing through the affected WordPress site's mail server, effectively turning the site into an open mail relay.

Public Exploits & PoCs5 found

[POC] CVE-2026-66752 — CVE-2026-66752-HTTP-Request-Smuggling-via-Unparsed-Transfer-Encoding-Values-tiny_http-

Security Advisory: HTTP Request Smuggling via Unparsed Transfer-Encoding Values (tiny_http)

[POC] CVE-2026-66753 — CVE-2026-66753-HTTP-Header-Injection-via-Unvalidated-CR-and-LF-in-Header-Values-tiny_http-

Security Advisory: HTTP Header Injection via Unvalidated CR and LF in Header Values (tiny_http)

[POC] CVE-2026-66754 — CVE-2026-66754-Remote-Denial-of-Service-via-Reachable-Assertion-in-URL-Prefix-Handling-rouille-

Security Advisory: Remote Denial of Service via Reachable Assertion in URL Prefix Handling (rouille)

[POC] CVE-2026-66750 — CVE-2026-66750-Insufficient-Access-Controls-Allow-for-Unauthorized-File-Downloads-Let-s-Chat-

Security Advisory: Insufficient Access Controls Allow for Unauthorized File Downloads (Let's Chat)

[POC] CVE-2026-66751 — CVE-2026-66751-Insufficient-Access-Controls-Allow-for-Unauthorized-Room-Deletion-Let-s-Chat-

Security Advisory: Insufficient Access Controls Allow for Unauthorized Room Deletion (Let's Chat)

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free