Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kaira Blockons blockons allows Stored XSS.This issue affects Blockons: from n/a through <= 1.2.19.
Published: 2026-01-23
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting
Action: Apply Patch
AI Analysis

Impact

The vulnerability is an improper neutralization of input during web page generation that allows an attacker to store malicious script code within the WordPress Blockons plugin. When the stored content is later rendered in a browser, the malicious code executes in the context of users who view the page, potentially allowing theft of session cookies, defacement, or other client‑side attacks. This reflects a classic Stored XSS weakness per CWE‑79.

Affected Systems

Kaira’s Blockons WordPress plugin for the Blockons blockons feature is affected on all releases up to and including 1.2.19. Any WordPress site that has installed these versions is potentially vulnerable.

Risk and Exploitability

The CVSS base score of 6.5 indicates a moderate impact. The EPSS score is less than 1 %, suggesting a very low exploitation probability at the moment of evaluation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector involves an adversary entering malicious script into a content field or form provided by the plugin, which is then stored and subsequently rendered to other site visitors. Users who view the affected page will have the injected script executed in their browsers, providing the attacker with client‑side capabilities.

Generated by OpenCVE AI on April 28, 2026 at 17:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Blockons plugin to a version later than 1.2.19, such as 1.2.20 or newer, which removes the stored‑XSS flaw.
  • If the plugin is not essential for site functionality, disable or uninstall Blockons to eliminate the risk.
  • Maintain an up‑to‑date WordPress core and other plugins, and regularly review plugin changelogs for security patches.

Generated by OpenCVE AI on April 28, 2026 at 17:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}

cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kaira Blockons blockons allows Stored XSS.This issue affects Blockons: from n/a through <= 1.2.15. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kaira Blockons blockons allows Stored XSS.This issue affects Blockons: from n/a through <= 1.2.19.
Title WordPress Blockons plugin <= 1.2.15 - Cross Site Scripting (XSS) vulnerability WordPress Blockons plugin <= 1.2.19 - Cross Site Scripting (XSS) vulnerability

Mon, 26 Jan 2026 12:00:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Fri, 23 Jan 2026 22:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 23 Jan 2026 14:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kaira Blockons blockons allows Stored XSS.This issue affects Blockons: from n/a through <= 1.2.15.
Title WordPress Blockons plugin <= 1.2.15 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References

Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:14:49.088Z

Reserved: 2026-01-23T12:31:51.715Z

Link: CVE-2026-24550

cve-icon Vulnrichment

Updated: 2026-01-23T21:28:29.352Z

cve-icon NVD

Status : Deferred

Published: 2026-01-23T15:16:11.547

Modified: 2026-04-28T15:16:13.130

Link: CVE-2026-24550

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-28T18:00:14Z

Weaknesses