Stored Cross-Site Scripting Vulnerability in Snow Monkey Blocks Plugin for WordPress
CVE-2026-3004

6.4MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
13 May 2026

What is CVE-2026-3004?

The Snow Monkey Blocks plugin for WordPress has a vulnerability allowing authenticated attackers, with Contributor-level access or higher, to exploit insufficient input sanitization and output escaping. This flaw is specifically related to the 'data-slick' attribute, which, when manipulated, enables the injection of arbitrary web scripts into pages. As a result, any user accessing an affected page may unknowingly trigger the malicious scripts, leading to potential data breaches and compromised user accounts.

Affected Version(s)

Snow Monkey Blocks 0 <= 24.1.11

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Muhammad Yudha - DJ
.