The Content Blocks (Custom Post Widget) plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to improper input sanitization and output escaping in its content_block shortcode. This vulnerability affects versions up to, and including, 3.3.9, allowing authenticated users with contributor-level access or higher to inject malicious scripts.
We use cookies to enhance your browsing experience, serve personalized ads or content, and analyze our traffic. By clicking "Accept All", you consent to our use of cookies.