Impact
The Cozy Blocks plugin allows authenticated users with contributor role or higher to edit block attributes. The cozyHoverEffect attribute is not sanitized or escaped but accepts a color value that can include a double‑quote to break out of the attribute. An attacker can insert malicious JavaScript which survives the wp_kses_post filter and runs when the page is rendered, giving the attacker ability to execute arbitrary scripts in the user’s browser.
Affected Systems
All installations of Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 700+ Patterns, 58 Blocks & Templates plugin, in versions up to and including 2.2.16, are affected.
Risk and Exploitability
The CVSS score of 6.4 indicates a medium severity. Because the EPSS score is not available, current exploitation likelihood is uncertain, and the vulnerability is not listed in the CISA KEV catalog, the overall risk remains moderate. Exploitation requires the attacker to have contributor or higher permission on the WordPress site and to deliver a payload that leverages the attribute’s lack of sanitization; once executed, client‑side script can steal credentials, perform actions via cross‑origin requests, or deface content.
OpenCVE Enrichment