Stored XSS in Zypento Blocks Plugin for WordPress
CVE-2026-5820
6.4MEDIUM
What is CVE-2026-5820?
The Zypento Blocks plugin for WordPress includes a vulnerability that allows for Stored Cross-Site Scripting (XSS) through the Table of Contents block. This issue arises from the use of innerText and innerHTML without appropriate sanitization, enabling authenticated users with Author-level permissions and above to inject malicious scripts into web pages. The injected scripts will execute when other users access the affected pages, posing significant security risks.
Affected Version(s)
Zypento Blocks 0 <= 1.06