Stored Cross-Site Scripting in CoBlocks Plugin for WordPress
CVE-2026-4801

6.4MEDIUM

What is CVE-2026-4801?

The CoBlocks plugin for WordPress is affected by a vulnerability that allows for Stored Cross-Site Scripting (XSS). This issue arises from insufficient output escaping of external iCal feed data, particularly in event titles, descriptions, and locations within the Events block rendering function. Authenticated attackers with Contributor-level access or higher can exploit this vulnerability to inject arbitrary web scripts. Such scripts will execute whenever a user accesses a compromised page, posing significant security risks to both the site's visitors and the integrity of the web application.

Affected Version(s)

Page Builder Gutenberg Blocks – CoBlocks 0 <= 3.1.16

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Fernando Mecozzi
.