Description
The Advance Block Extend plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the TitleColor block attribute in the Latest Posts Gutenberg block in all versions up to, and including, 1.0.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Published: 2026-02-19
Score: 6.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting
Action: Patch Now
AI Analysis

Impact

The Advance Block Extend plugin for WordPress is vulnerable to stored cross‑site scripting through the TitleColor attribute of the Latest Posts Gutenberg block. Because the plugin does not sanitize or escape this attribute, an authenticated user with Contributor level or higher can inject arbitrary JavaScript. When an affected user loads a page containing the injected block, the malicious script runs in the visitor's browser, enabling cookie theft, phishing, or other client‑side attacks. This flaw represents a classic injection weakness (CWE‑79).

Affected Systems

The vulnerability affects the Advance Block Extend plugin distributed by iamjaydip, known as the Advance Block Extend plugin, for all WordPress installations that have versions up to and including 1.0.4. Any WordPress site that has installed this plugin and has users with Contributor or higher roles is susceptible. No other products or versions are impacted according to the vendor information.

Risk and Exploitability

The CVSS v3 base score of 6.4 classifies this flaw as medium severity, but the EPSS score of less than 1% indicates a very low probability of widespread exploitation at present. Because the flaw requires authenticated Contributor or admin access, attackers must first compromise legitimate credentials or obtain a high‑privilege role. The vulnerability is not listed in the CISA KEV catalog, further suggesting limited active exploitation. Nonetheless, once a site owner authorizes a contributor, they could inject payloads that run for every visitor to the site, potentially affecting large traffic volumes. The necessary access level and lack of an immediate public exploit keep the risk moderate but non‑negligible for active WordPress sites relying on this plugin.

Generated by OpenCVE AI on April 15, 2026 at 18:12 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Advance Block Extend plugin to version 1.0.5 or later, which removes the vulnerable TitleColor attribute handling.
  • If upgrading is not feasible, add a server‑side filter that strips or sanitizes the TitleColor attribute from the Latest Posts block to prevent script injection.
  • Reduce the risk of exploitation by limiting Contributor privileges so they cannot edit block attributes, or temporarily remove Contributor users from the site until the vulnerability is resolved.

Generated by OpenCVE AI on April 15, 2026 at 18:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 19 Feb 2026 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 19 Feb 2026 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Iamjaydip
Iamjaydip advance Block Extend
Wordpress
Wordpress wordpress
Vendors & Products Iamjaydip
Iamjaydip advance Block Extend
Wordpress
Wordpress wordpress

Thu, 19 Feb 2026 05:00:00 +0000

Type Values Removed Values Added
Description The Advance Block Extend plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the TitleColor block attribute in the Latest Posts Gutenberg block in all versions up to, and including, 1.0.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Title Advance Block Extend <= 1.0.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via TitleColor Block Attribute
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

Iamjaydip Advance Block Extend
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-04-08T16:45:15.753Z

Reserved: 2026-01-29T18:41:12.628Z

Link: CVE-2026-1646

cve-icon Vulnrichment

Updated: 2026-02-19T17:03:58.859Z

cve-icon NVD

Status : Deferred

Published: 2026-02-19T07:17:44.233

Modified: 2026-04-15T00:35:42.020

Link: CVE-2026-1646

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-15T18:15:10Z

Weaknesses