PT-2026-47690 · WordPress · Custom Block Builder

·

CVE-2026-8981

·

Published

2026-06-09

·

Updated

2026-06-09

CVSS v3.1

3.5

Low

VectorAV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Custom Block Builder versions prior to 4.3.0
Description The plugin fails to consistently verify the unfiltered html capability across all paths that write to block template code fields. This allows administrators on multisite installations, or single-site installations where DISALLOW UNFILTERED HTML is defined, to perform a stored cross-site scripting (XSS) attack by injecting arbitrary JavaScript. This script executes for any visitor who views pages embedding the affected block.
Recommendations Update to version 4.3.0 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-8981

Affected Products

Custom Block Builder