Stored Cross-Site Scripting Vulnerability in Cozy Blocks for WordPress
CVE-2026-15950
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 1 August 2026
What is CVE-2026-15950?
The Cozy Blocks β Page Builder for Gutenberg Editor & FSE plugin for WordPress is susceptible to a Stored Cross-Site Scripting vulnerability. This issue arises from insufficient input sanitization and output escaping associated with the 'layoutCircle.alignment' Block Attribute in versions up to 2.2.11. Authenticated attackers, who possess contributor-level access and higher, have the ability to inject malicious scripts into web pages. These injected scripts execute whenever a user visits an affected page, potentially compromising user security and data integrity.
Affected Version(s)
Cozy Blocks β Page Builder for Gutenberg Editor & FSE with 700+ Patterns, 58 Blocks & Templates 0 <= 2.2.11