Description
The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'postMeta.font.size' Block Attribute in all versions up to, and including, 2.2.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Published: 2026-07-28
Score: 6.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Cozy Blocks plugin for WordPress stores the value of the block attribute 'postMeta.font.size' without sufficient sanitization or escaping. An authenticated user with contributor or higher privileges can supply malicious content for this attribute, which is later rendered as part of a page. The injected script runs in the browser context whenever any user visits the page, enabling data theft, session hijacking, defacement, or further hosting of malware. The flaw is a classic stored XSS identified as CWE‑79.

Affected Systems

Vulnerable versions of Cozy Blocks are all releases up to and including 2.2.11. The plugin is widely deployed in WordPress installations, offering more than 600 design patterns, 58 blocks, and templates. Site administrators and contributors who can create or edit blocks are the likely threat actors; any authenticated visitor to the site can be impacted by the injected code.

Risk and Exploitability

The CVSS score for this vulnerability is 6.4, indicating a moderate impact when exploitation is feasible. EPSS is reported as <1%, implying that real‑world exploitation is currently unlikely but not impossible. The vulnerability is not listed in the CISA KEV catalog. Attackers would need to authenticate to the WordPress site as a contributor or higher, then create or edit a block to inject script payloads. Once the script is stored, any user viewing the page will execute it without additional interaction.

Generated by OpenCVE AI on August 4, 2026 at 12:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Cozy Blocks to the latest available version, which includes the required input sanitization and output escaping fixes.
  • If an immediate upgrade is not possible, enforce role‑based access controls that limit contributors and higher roles from editing or creating blocks, ensuring only administrators can modify block content.
  • Perform a comprehensive audit of stored block content to identify and remove any injected scripts or malicious code.

Generated by OpenCVE AI on August 4, 2026 at 12:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
Link Providers
https://plugins.trac.wordpress.org/browser/cozy-addons/tags/2.2.10/blocks/categorized-post-tabs/render.php#L1 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/cozy-addons/tags/2.2.10/includes/Helpers/class-block-render.php#L512 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/cozy-addons/tags/2.2.10/includes/Helpers/class-block-render.php#L513 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/cozy-addons/tags/2.2.10/includes/Helpers/class-block-render.php#L531 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/cozy-addons/tags/2.2.10/includes/Helpers/class-block-render.php#L532 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/cozy-addons/tags/2.2.10/includes/Helpers/class-block-render.php#L550 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/cozy-addons/tags/2.2.10/includes/Helpers/class-block-render.php#L551 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/cozy-addons/tags/2.2.11/blocks/categorized-post-tabs/render.php#L1 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/cozy-addons/tags/2.2.11/includes/Helpers/class-block-render.php#L512 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/cozy-addons/tags/2.2.11/includes/Helpers/class-block-render.php#L513 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/cozy-addons/tags/2.2.11/includes/Helpers/class-block-render.php#L531 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/cozy-addons/tags/2.2.11/includes/Helpers/class-block-render.php#L532 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/cozy-addons/tags/2.2.11/includes/Helpers/class-block-render.php#L550 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/cozy-addons/tags/2.2.11/includes/Helpers/class-block-render.php#L551 cve-icon cve-icon
https://plugins.trac.wordpress.org/changeset?reponame=&old=3619461%40cozy-addons&new=3619461%40cozy-addons cve-icon cve-icon
https://www.wordfence.com/threat-intel/vulnerabilities/id/e93de7ae-c3a8-4536-9c07-e64d7746e05f?source=cve cve-icon cve-icon
History

Tue, 28 Jul 2026 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Cozythemes
Cozythemes cozy Blocks – Page Builder For Gutenberg Editor & Fse With 600+ Patterns, 58 Blocks & Templates
Wordpress
Wordpress wordpress
Vendors & Products Cozythemes
Cozythemes cozy Blocks – Page Builder For Gutenberg Editor & Fse With 600+ Patterns, 58 Blocks & Templates
Wordpress
Wordpress wordpress

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Description The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'postMeta.font.size' Block Attribute in all versions up to, and including, 2.2.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Title Cozy Blocks <= 2.2.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'postMeta.font.size' Block Attribute
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Cozythemes Cozy Blocks – Page Builder For Gutenberg Editor & Fse With 600+ Patterns, 58 Blocks & Templates
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-07-28T13:26:49.122Z

Reserved: 2026-07-10T13:02:10.347Z

Link: CVE-2026-15393

cve-icon Vulnrichment

Updated: 2026-07-28T13:26:45.525Z

cve-icon NVD

Status : Deferred

Published: 2026-07-28T13:17:34.697

Modified: 2026-07-28T16:07:15.840

Link: CVE-2026-15393

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T13:00:11Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')