Reflected Cross-Site Scripting Vulnerability in WP Blockade Plugin by WordPress
CVE-2026-3481
6.1MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 22 May 2026
What is CVE-2026-3481?
The WP Blockade plugin for WordPress is susceptible to Reflected Cross-Site Scripting (XSS) via the 'shortcode' parameter. This vulnerability arises from inadequate input sanitization and output escaping in the render_shortcode_preview() function. User input is processed directly without proper validation, allowing authenticated users with Subscriber-level access to inject malicious scripts. If an attacker tricks another user into clicking a crafted link, the injected scripts may execute in the context of their session, potentially compromising sensitive information and site integrity.
Affected Version(s)
WP Blockade β Visual Page Builder 0 <= 0.9.14