Impact
Magazine Blocks for WordPress contains a stored cross‑site scripting flaw in the News Ticker block. The clientId attribute is concatenated into an HTML class attribute in the render() function without the necessary esc_attr() sanitization. This weakness aligns with CWE‑79. Consequently, an attacker who can create or edit a block with contributor or higher privileges can inject arbitrary JavaScript. When authenticated, the attacker stores the malicious payload; any visitor who loads a page containing the affected block will execute the script, potentially exfiltrating data, defacing the site, or delivering further attacks.
Affected Systems
All installations of the Magazine Blocks plugin – including the Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, and Post Grid extensions – are impacted if the version is 1.8.6 or earlier. The vulnerability exists in all releases up to and including 1.8.6. The affected product is provided by wpblockart.
Risk and Exploitability
The CVSS score of 6.4 classifies the vulnerability as medium severity, while the EPSS value of less than 1% indicates a very low probability that this weakness will be exploited in the wild. The flaw is not listed in CISA’s Known Exploited Vulnerabilities catalog. An attacker would need authenticated access with contributor‑level permissions or higher, and would use the WordPress block editor to submit a malicious clientId value; no remote code execution on the server is required, but any site visitor with the compromised page load will run the payload. The lack of sanitization makes the attack relatively easy for an attacker with the necessary privileges.
OpenCVE Enrichment