MEDIUM (6.8)
    Plugin

    Stored Cross-Site Scripting in Content Blocks Plugin

    Published Date: 4/18/2026
    CVE ID: CVE-2026-0894

    Summary

    The Content Blocks (Custom Post Widget) plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to improper input sanitization and output escaping in its content_block shortcode. This vulnerability affects versions up to, and including, 3.3.9, allowing authenticated users with contributor-level access or higher to inject malicious scripts.

    Vulnerability Details

    This vulnerability arises from how the Content Blocks plugin processes user input into content blocks via shortcodes, without adequate sanitization or escaping. Because the input is not properly sanitized, an attacker with sufficient access privileges can inject scripts that are stored within the WordPress database. When another user accesses a page with the injected malicious content, the scripts execute in their browser's context, potentially leading to session hijacking, defacement, or other malicious activities. Stored XSS vulnerabilities pose a significant threat as they affect all users who load the affected page, bypassing standard security protocols like content security policy (CSP) that rely on static content analysis. The fact that this vulnerability requires contributor-level access limits its exploitability but can be severely damaging within multi-author environments.

    Recommendations

    To mitigate this vulnerability, restrict the use of the vulnerable plugin to trusted users only and consider employing a security plugin that provides input validation and output sanitization features. Regularly review user roles and permissions to minimize the number of accounts with contributor access. Additionally, educate users on recognizing potentially malicious activity and adhering to best practices when creating content.

    Available Fixes

    Last Updated: 4/19/2026
    Jedar

    Jedar for Digital Rights is a non-profit organization dedicated to protecting digital freedoms, enhancing online privacy, and promoting secure digital practices for vulnerable communities worldwide.

    Follow Us

    All Rights Reserved © 2026 Jedar for Digital Rights.

    Cookie Preferences

    We use cookies to enhance your browsing experience, serve personalized ads or content, and analyze our traffic. By clicking "Accept All", you consent to our use of cookies.

    Learn More