Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kodezen LLC aBlocks ablocks allows Reflected XSS.This issue affects aBlocks: from n/a through 2.16.0.
Published: 2026-10-08
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: Reflected cross‑site scripting
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is an improper neutralization of input during web page generation, allowing attackers to inject arbitrary Javascript via reflected XSS. An attacker can craft a malicious URL or form payload that causes the browser to execute code in the context of the victim's session, enabling cookie theft, session hijacking, defacement or redirecting users to malicious sites.

Affected Systems

The flaw exists in the aBlocks WordPress plugin developed by Kodezen LLC. All releases from the earliest available version up to and including 2.16.0 are affected. Sites that have this plugin installed and serve it to visitors are vulnerable.

Risk and Exploitability

The CVSS score is 7.1, indicating high severity for client‑side impact. The EPSS score is not available, and the vulnerability is not listed in CISA KEV. The attack vector is public web‑based; no authentication is required. Exploitation is straightforward for malicious actors who can embed the offending payload in a link or web form, and users who click the link or submit the form will be affected.

Generated by OpenCVE AI on October 8, 2026 at 20:26 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the aBlocks plugin to the latest version (v2.17.0 or later) that removes the XSS flaw.
  • If an update is not yet available, completely disable or uninstall the aBlocks plugin to eliminate the attack surface.
  • As a temporary measure, configure a web application firewall or use plugin security settings to sanitize user input and block scripts in query strings or form fields.

Generated by OpenCVE AI on October 8, 2026 at 20:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 08 Oct 2026 19:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kodezen LLC aBlocks ablocks allows Reflected XSS.This issue affects aBlocks: from n/a through 2.16.0.
Title WordPress aBlocks plugin <= 2.16.0 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-08T19:29:11.917Z

Reserved: 2026-04-15T09:21:11.865Z

Link: CVE-2026-40804

cve-icon Vulnrichment

Updated: 2026-10-08T19:29:07.020Z

cve-icon NVD

Status : Deferred

Published: 2026-10-08T19:17:05.170

Modified: 2026-10-08T20:17:36.343

Link: CVE-2026-40804

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T20:30:18Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')