Stored XSS in Zypento Blocks Plugin for WordPress
CVE-2026-5820

6.4MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
22 April 2026

What is CVE-2026-5820?

The Zypento Blocks plugin for WordPress includes a vulnerability that allows for Stored Cross-Site Scripting (XSS) through the Table of Contents block. This issue arises from the use of innerText and innerHTML without appropriate sanitization, enabling authenticated users with Author-level permissions and above to inject malicious scripts into web pages. The injected scripts will execute when other users access the affected pages, posing significant security risks.

Affected Version(s)

Zypento Blocks 0 <= 1.06

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Athiwat Tiprasaharn
.