PT-2026-50626 · WordPress · Services Section Block

·

CVE-2026-11402

·

Published

2026-06-18

·

Updated

2026-06-18

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Services Section Block – Showcase Service Details in Grid or Columns versions prior to 1.4.5
Description Insufficient input sanitization and output escaping allow authenticated attackers with contributor-level access or higher to perform Stored Cross-Site Scripting. This is achieved via the link block attribute, where arbitrary web scripts can be injected into pages. The payload persists within HTML comments in post content, bypassing the wp kses post() sanitization function during the save process. The script executes through the primary service link anchor or a secondary title-wrapped anchor when the linkIn option is set to title.
Recommendations Update to a version later than 1.4.4.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-11402

Affected Products

Services Section Block