Stored Cross-Site Scripting Vulnerability in Snow Monkey Blocks Plugin for WordPress
CVE-2026-3004
6.4MEDIUM
What is CVE-2026-3004?
The Snow Monkey Blocks plugin for WordPress has a vulnerability allowing authenticated attackers, with Contributor-level access or higher, to exploit insufficient input sanitization and output escaping. This flaw is specifically related to the 'data-slick' attribute, which, when manipulated, enables the injection of arbitrary web scripts into pages. As a result, any user accessing an affected page may unknowingly trigger the malicious scripts, leading to potential data breaches and compromised user accounts.
Affected Version(s)
Snow Monkey Blocks 0 <= 24.1.11