Impact
An unauthenticated cross‑site scripting flaw exists in the WordPress Toolset Blocks plugin through version 1.6.26. The flaw allows an attacker to inject arbitrary client‑side script into the site’s block content, which will run in the browsers of visitors. This can result in cookie theft, session hijacking, defacement, or the execution of further malicious payloads within the user’s context.
Affected Systems
WordPress sites that have the Site Building with Toolset: Toolset Blocks plugin installed at version 1.6.26 or earlier. Any user who creates or edits block content could be impacted if the site allows unauthenticated input of block parameters.
Risk and Exploitability
The flaw has a CVSS score of 7.1, indicating a moderate to high severity. EPSS information is not available, and the vulnerability is not listed in CISA’s KEV catalog. The attack vector is unauthenticated, meaning any visitor can trigger the vulnerability by submitting crafted block content or manipulating block parameters. Successful exploitation grants an attacker the ability to inject executable script that runs in the context of site visitors, potentially leading to data exfiltration, session hijack, or defacement.
OpenCVE Enrichment