Impact
The Cozy Blocks plugin for WordPress has a stored cross‑site scripting flaw (CWE‑79) that allows an authenticated contributor or higher to inject arbitrary scripts into the 'cozyCustomFont' block attribute. Because the data is not properly sanitized or escaped, the script is saved and executed each time an affected page is viewed, enabling malicious code to run in users' browsers when they load the page.
Affected Systems
All WordPress sites running Cozy Blocks – Page Builder for Gutenberg Editor & FSE plugin version 2.2.11 or earlier are vulnerable. Any user who installs the vulnerable plugin on their site and has Contributor‑level access or greater can exploit the flaw.
Risk and Exploitability
The vulnerability has a CVSS score of 6.4, indicating a moderate severity. The EPSS score is less than 1 %, suggesting a low current exploitation probability. It is not listed in the CISA KEV catalog. Exploitation requires authenticated access with at least Contributor permissions; the attacker can then insert malicious scripts that will execute for any user who views the affected page.
OpenCVE Enrichment