Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins Icon List Block icon-list-block allows Stored XSS.This issue affects Icon List Block: from n/a through <= 1.2.3.
Published: 2026-03-13
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting
Action: Apply Patch
AI Analysis

Impact

The bPlugins Icon List Block plugin contains a stored cross‑site scripting (XSS) flaw caused by improper neutralization of user‑supplied input during web page generation. This vulnerability allows an attacker to embed malicious script code into the icon‑list block content, which will execute in the browsers of any visitor who views that content. The resulting impact can include cookie theft, session hijacking, defacement, or execution of arbitrary client‑side code, thereby compromising confidentiality and potentially integrity of user data. The weakness is classified as CWE‑79 (Improper Neutralization of Input).

Affected Systems

Affected systems are WordPress sites that have installed the bPlugins Icon List Block plugin. All versions from the first release (n/a) through version 1.2.3 are vulnerable. No other plugins or components are listed as affected in the CVE data.

Risk and Exploitability

The CVSS v3.1 score of 6.5 indicates moderate severity. The EPSS score is below 1 %, indicating a low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker would need authenticated access to a post or page editor with permission to modify content in order to inject malicious payloads. Unauthenticated attackers would therefore require additional compromise or privilege escalation to deliver the payload. The likely attack vector is through the WordPress administration interface where the icon‑list block is edited.

Generated by OpenCVE AI on March 17, 2026 at 17:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Verify that the installed Icon List Block plugin version is 1.2.3 or earlier.
  • If so, upgrade the plugin to the latest release available from the official WordPress Plugin Repository.
  • If an upgrade cannot be performed immediately, temporarily disable the Icon List Block plugin to prevent further exploitation.
  • After upgrading or disabling, review all existing posts or pages that use the icon‑list block and remove or sanitize any content that may contain injected scripts.

Generated by OpenCVE AI on March 17, 2026 at 17:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 16 Mar 2026 14:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 16 Mar 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Bplugins
Bplugins icon List Block
Wordpress
Wordpress wordpress
Vendors & Products Bplugins
Bplugins icon List Block
Wordpress
Wordpress wordpress

Fri, 13 Mar 2026 12:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins Icon List Block icon-list-block allows Stored XSS.This issue affects Icon List Block: from n/a through <= 1.2.3.
Title WordPress Icon List Block plugin <= 1.2.3 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References

Subscriptions

Bplugins Icon List Block
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-01T14:15:58.629Z

Reserved: 2026-03-12T11:10:53.773Z

Link: CVE-2026-32359

cve-icon Vulnrichment

Updated: 2026-03-16T13:49:33.793Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-03-13T19:54:49.667

Modified: 2026-03-16T14:53:46.157

Link: CVE-2026-32359

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-03-23T09:58:58Z

Weaknesses