Impact
This vulnerability is a contributor Cross Site Scripting (XSS) flaw in the Premium Blocks – Gutenberg Blocks for WordPress plugin up to version 2.3.17. An attacker can inject arbitrary scripts that are rendered when the block editor or the front end displays the content. The plugin does not properly sanitize user input in the block editor, allowing malicious JavaScript to execute in the context of anyone who views the affected content. The potential impact is compromised client‑side security for users who access the edited content.
Affected Systems
Leap13’s Premium Blocks – Gutenberg Blocks for WordPress plugin, all releases through 2.3.17, is affected. Sites running any of these versions with contributors who can create or edit blocks are at risk.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, the EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves an authenticated contributor who can insert or modify blocks; the attacker must have valid credentials to exploit the flaw. Because the vulnerability lacks widespread exploitation data and is not in KEV, the overall risk is moderate, but applying the patch is strongly recommended to eliminate the XSS vector.
OpenCVE Enrichment