WordPress · Essential Blocks For Gutenberg · CVE-2026-10833
**Name of the Vulnerable Software and Affected Versions**
Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns versions prior to 6.1.5
**Description**
Insufficient input sanitization and output escaping allow authenticated attackers with Contributor-level access and above to perform Stored Cross-Site Scripting. This is achieved by injecting arbitrary web scripts through the `configurablePrefix` Block Attribute, which execute when a user visits the affected page.
**Recommendations**
Update to version 6.1.5 or later.