Stored Cross-Site Scripting in Post Blocks & Tools Plugin for WordPress
CVE-2026-5711
6.4MEDIUM
What is CVE-2026-5711?
The Post Blocks & Tools plugin for WordPress is susceptible to a Stored Cross-Site Scripting vulnerability due to inadequate input sanitization and output escaping for the 'sliderStyle' block attribute. Authenticated users with author-level access can exploit this weakness to inject arbitrary web scripts into pages. When a user accesses an affected page, these scripts will execute, potentially compromising the security of affected sites.
Affected Version(s)
Post Blocks & Tools 0 <= 1.3.0