Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in devscred Design Blocks exclusive-blocks allows Stored XSS.This issue affects Design Blocks: from n/a through <= 1.2.5.
Published: 2025-04-01
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is an improper neutralization of input during web page generation, allowing storage of arbitrary client‑side script by the Design Blocks plugin. The injected script can execute in the browsers of users who view the affected content. Based on the description, it is inferred that an attacker might abuse this to steal credentials, hijack sessions, or deface the site. The weakness is classified as CWE‑79 and does not allow remote code execution or direct server compromise.

Affected Systems

WordPress sites that use the devscred Design Blocks exclusive‑blocks plugin, versions from the earliest available release through 1.2.5 inclusive. Any installation of this plugin within that version range is vulnerable.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity, while the EPSS score of less than 1% indicates a low probability of public exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires that an attacker be able to submit content that the plugin stores. Based on the description, it is inferred that submission may be possible only by users with block‑creation privileges, such as authenticated users or administrators. Once stored, the payload affects all visitors who render the compromised block. Due to the lack of a more direct attack vector, the practical impact is limited to the web‑client environment of site visitors.

Generated by OpenCVE AI on May 1, 2026 at 11:47 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Design Blocks exclusive‑blocks plugin to a version newer than 1.2.5 or the latest release available from the vendor.
  • If an update is not yet released, disable or uninstall the plugin to eliminate the input vector that stores malicious scripts.
  • Monitor site content for unexpected script tags or changes in block behaviour, and implement a web application firewall rule to block known XSS payloads until a patch is applied.

Generated by OpenCVE AI on May 1, 2026 at 11:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-9220 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in devscred Design Blocks allows Stored XSS. This issue affects Design Blocks: from n/a through 1.2.2.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in devscred Design Blocks allows Stored XSS. This issue affects Design Blocks: from n/a through 1.2.2. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in devscred Design Blocks exclusive-blocks allows Stored XSS.This issue affects Design Blocks: from n/a through <= 1.2.5.
Title WordPress Design Blocks plugin <= 1.2.2 - Cross Site Scripting (XSS) vulnerability WordPress Design Blocks plugin <= 1.2.5 - Cross Site Scripting (XSS) vulnerability
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Tue, 01 Apr 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 01 Apr 2025 15:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in devscred Design Blocks allows Stored XSS. This issue affects Design Blocks: from n/a through 1.2.2.
Title WordPress Design Blocks plugin <= 1.2.2 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:13.353Z

Reserved: 2025-04-01T13:20:24.607Z

Link: CVE-2025-31815

cve-icon Vulnrichment

Updated: 2025-04-01T20:03:53.994Z

cve-icon NVD

Status : Deferred

Published: 2025-04-01T15:16:21.343

Modified: 2026-04-23T15:28:20.990

Link: CVE-2025-31815

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T12:00:15Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')