Impact
The All Bootstrap Blocks WordPress plugin version 1.3.31 and earlier fails to escape a block attribute that is inserted into the HTML tag name. An attacker with contributor or higher privileges can inject arbitrary JavaScript into that attribute, which executes when a viewer loads the content. This stored cross‑site scripting can steal credentials, hijack sessions, or load malicious payloads in the context of site visitors.
Affected Systems
All installations of the All Bootstrap Blocks plugin that use version 1.3.31 or older are affected. The issue is specific to the plugin and can impact any WordPress site that has the plugin enabled, regardless of the WordPress core version.
Risk and Exploitability
With a CVSS score of 6.8 the flaw presents medium severity. The EPSS score of less than 1 % suggests a low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Attackers must first obtain contributor or higher level access to create or edit a block; once the malicious script is stored it runs in the browsers of any visitor to the affected content, making the risk considerable in high‑traffic or low‑privilege environments.
OpenCVE Enrichment