PT-2026-50626 · WordPress · Services Section Block
CVSS v3.1
6.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Services Section Block – Showcase Service Details in Grid or Columns versions prior to 1.4.5
Description
Insufficient input sanitization and output escaping allow authenticated attackers with contributor-level access or higher to perform Stored Cross-Site Scripting. This is achieved via the
link block attribute, where arbitrary web scripts can be injected into pages. The payload persists within HTML comments in post content, bypassing the wp kses post() sanitization function during the save process. The script executes through the primary service link anchor or a secondary title-wrapped anchor when the linkIn option is set to title.Recommendations
Update to a version later than 1.4.4.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Services Section Block