Impact
The Post Blocks & Tools WordPress plugin contains a stored XSS flaw where the headerHtmlTag attribute in the featured‑posts block accepts unsanitised user input and outputs it directly as an HTML tag name. An attacker who can edit content as a contributor, editor or administrator can craft an arbitrary JavaScript payload in this field. When the crafted block is displayed, the payload runs in the context of any visitor’s browser, which can lead to credential theft, defacement or session hijacking.
Affected Systems
All installations of the Post Blocks & Tools plugin version 1.2.3 or earlier for WordPress are susceptible. The flaw exists in a single block module used by the plugin and does not affect WordPress core or other plugins directly.
Risk and Exploitability
The CVSS score of 6.4 indicates a moderate risk, and the EPSS score of less than 1% shows a low probability of exploitation in the current landscape. Because the attack requires authenticated contributor‑level access, it is generally limited to sites with an attacker who has compromised an existing user account. The flaw is not listed in the CISA KEV catalog, but the ability to subvert site security remains significant for targeted attacks.
OpenCVE Enrichment