PT-2026-47690 · WordPress · Custom Block Builder
CVSS v3.1
3.5
Low
| Vector | AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Custom Block Builder versions prior to 4.3.0
Description
The plugin fails to consistently verify the
unfiltered html capability across all paths that write to block template code fields. This allows administrators on multisite installations, or single-site installations where DISALLOW UNFILTERED HTML is defined, to perform a stored cross-site scripting (XSS) attack by injecting arbitrary JavaScript. This script executes for any visitor who views pages embedding the affected block.Recommendations
Update to version 4.3.0 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Custom Block Builder