Stored Cross-Site Scripting in CoBlocks Plugin for WordPress
CVE-2026-4801
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 18 April 2026
What is CVE-2026-4801?
The CoBlocks plugin for WordPress is affected by a vulnerability that allows for Stored Cross-Site Scripting (XSS). This issue arises from insufficient output escaping of external iCal feed data, particularly in event titles, descriptions, and locations within the Events block rendering function. Authenticated attackers with Contributor-level access or higher can exploit this vulnerability to inject arbitrary web scripts. Such scripts will execute whenever a user accesses a compromised page, posing significant security risks to both the site's visitors and the integrity of the web application.
Affected Version(s)
Page Builder Gutenberg Blocks β CoBlocks 0 <= 3.1.16