Description
Unauthenticated Cross Site Scripting (XSS) in Toolset Blocks <= 1.6.26 versions.
Published: 2026-08-24
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An unauthenticated cross‑site scripting flaw exists in the WordPress Toolset Blocks plugin through version 1.6.26. The flaw allows an attacker to inject arbitrary client‑side script into the site’s block content, which will run in the browsers of visitors. This can result in cookie theft, session hijacking, defacement, or the execution of further malicious payloads within the user’s context.

Affected Systems

WordPress sites that have the Site Building with Toolset: Toolset Blocks plugin installed at version 1.6.26 or earlier. Any user who creates or edits block content could be impacted if the site allows unauthenticated input of block parameters.

Risk and Exploitability

The flaw has a CVSS score of 7.1, indicating a moderate to high severity. EPSS information is not available, and the vulnerability is not listed in CISA’s KEV catalog. The attack vector is unauthenticated, meaning any visitor can trigger the vulnerability by submitting crafted block content or manipulating block parameters. Successful exploitation grants an attacker the ability to inject executable script that runs in the context of site visitors, potentially leading to data exfiltration, session hijack, or defacement.

Generated by OpenCVE AI on August 24, 2026 at 22:26 UTC.

Remediation

Vendor Solution

Update the WordPress Toolset Blocks Plugin to the latest available version (at least 1.6.27).


OpenCVE Recommended Actions

  • Update the WordPress Toolset Blocks Plugin to version 1.6.27 or later.
  • Search existing content for injected script and remove any malicious code from posts, pages, or custom block instances.
  • Configure a web application firewall or security plugin to block XSS payloads and enforce input validation on all blocks and form fields.

Generated by OpenCVE AI on August 24, 2026 at 22:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated Cross Site Scripting (XSS) in Toolset Blocks <= 1.6.26 versions.
Title WordPress Toolset Blocks plugin <= 1.6.26 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-24T21:31:32.102Z

Reserved: 2026-08-24T07:37:35.411Z

Link: CVE-2026-78264

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-24T22:17:20.267

Modified: 2026-08-24T22:17:20.267

Link: CVE-2026-78264

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T22:30:04Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')