Stored Cross-Site Scripting Vulnerability in Cozy Blocks Plugin for WordPress
CVE-2026-15393
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 28 July 2026
What is CVE-2026-15393?
The Cozy Blocks plugin, designed for WordPress, is prone to a Stored Cross-Site Scripting vulnerability due to insufficient sanitization of the 'postMeta.font.size' block attribute. This issue affects all versions up to and including 2.2.11. Authenticated attackers with contributor-level access or higher can exploit this vulnerability to inject arbitrary web scripts into pages. The injected scripts will execute whenever a user visits the affected page, potentially compromising user data and site integrity.
Affected Version(s)
Cozy Blocks β Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates 0 <= 2.2.11