Impact
Contributor Cross Site Scripting (XSS) is present in Magazine Blocks plugin versions up to 1.8.6. The flaw allows code to be inserted into a block editor by the contributor role and then rendered as part of the front‑end output. Once executed, the script can modify page content, steal cookies or session data, and redirect users to malicious sites, thereby damaging confidentiality, integrity, and trust in the site.
Affected Systems
The vulnerability affects all installations of the ThemeGrill Magazine Blocks WordPress plugin that are at or below version 1.8.6. Users should verify the plugin version and check for any contributor‑generated blocks that may contain untrusted content.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. The EPSS score is not available, so current exploitation likelihood cannot be quantified. The vulnerability is not listed in the CISA KEV catalog. Attackers likely need to have at least contributor permissions to inject the malicious code, which is inferred from the “Contributor XSS” description. Once injected, the script runs in the visitor's browser, providing remote code execution on the client side.
OpenCVE Enrichment