Impact
The vulnerability is a stored cross‑site scripting (XSS) flaw triggered by an insufficiently sanitized block attribute named ‘icon.view’ in the Cozy Blocks‑for‑WordPress plugin. An attacker with contributor‑level or higher permissions can inject arbitrary JavaScript into a page, and the code will execute whenever any site visitor accesses that page.
Affected Systems
The affected product is the Cozy Blocks – Page Builder for Gutenberg Editor & FSE plugin for WordPress. All releases up to and including version 2.2.11 contain the flaw, and the issue exists in any WordPress site that has installed those versions and allows contributor or higher users to edit blocks or pages.
Risk and Exploitability
The CVSS score of 6.4 indicates moderate severity; however, the EPSS is listed as less than 1%, suggesting a very low likelihood of exploitation at this time. The vulnerability is not in the CISA KEV catalog, so there is no publicly disclosed exploit. The attack vector requires authenticated access with at least contributor privileges, meaning that a site administrator would need to grant or already possess such permissions. If an attacker gains these credentials, they can permanently embed malicious script into site content that affects all users who view the affected page.
OpenCVE Enrichment