Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins B Blocks b-blocks allows Stored XSS.This issue affects B Blocks: from n/a through 2.1.8.
Published: 2026-10-05
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: Stored Cross‑Site Scripting
Action: Immediate Patch
AI Analysis

Impact

The vulnerability arises from improper neutralization of user input when rendering web pages, allowing an attacker to store malicious JavaScript code in WordPress content. When a user views the compromised page, the injected script runs in their browser, potentially stealing credentials, hijacking sessions, or defacing the site. This flaw permits arbitrary code execution in the context of the victim’s browser, jeopardizing confidentiality, integrity, and the user experience. The weakness is identified as CWE‑79, which reflects insufficient sanitization of user-supplied data.

Affected Systems

This flaw affects the bPlugins B Blocks plugin for WordPress, specifically all releases up to version 2.1.8 inclusive. The vulnerability is present from the earliest version (n/a) through 2.1.8, and users of any of these versions are at risk if the plugin is activated on a live site.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity, and currently the EPSS score is unavailable, so the exploitation probability cannot be quantified precisely. The vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed widespread exploitation at this time. However, stored XSS is a common attack vector and can be triggered by any user with permission to add or edit content that the plugin processes. An attacker controlling content input could embed malicious scripts that execute for all visitors who view the affected pages, making the risk contingent on the plugin’s use case and the site’s access controls.

Generated by OpenCVE AI on October 5, 2026 at 09:21 UTC.

Remediation

Vendor Solution

Update the WordPress B Blocks plugin to the latest available version (at least 2.1.9).


OpenCVE Recommended Actions

  • Update the WordPress B Blocks plugin to version 2.1.9 or later, the first official fix for this issue.
  • Remove any cached or residual files from older plugin versions that may still be present on the server to prevent old, vulnerable code from running.
  • If an update cannot be performed immediately, disable or uninstall the plugin to eliminate the attack surface until a patch is applied.

Generated by OpenCVE AI on October 5, 2026 at 09:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 08:30:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins B Blocks b-blocks allows Stored XSS.This issue affects B Blocks: from n/a through 2.1.8.
Title WordPress B Blocks plugin <= 2.1.8 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-05T08:07:36.319Z

Reserved: 2026-10-02T00:22:13.105Z

Link: CVE-2026-104400

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-05T09:17:08.067

Modified: 2026-10-05T09:17:08.067

Link: CVE-2026-104400

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T09:30:10Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')