Stored Cross-Site Scripting Vulnerability in Magazine Blocks Plugin for WordPress
CVE-2026-75016
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 18 September 2026
What is CVE-2026-75016?
The Magazine Blocks plugin for WordPress is vulnerable to stored cross-site scripting through the News Ticker block's clientId attribute in versions 1.8.6 and earlier. This vulnerability arises from inadequate input sanitization and output escaping within the NewsTicker::render() method, where the clientId block attribute is concatenated into an HTML class attribute without proper escaping. As a result, authenticated attackers with contributor-level access or higher can inject malicious web scripts into pages, leading to potential execution when users access those pages.
Affected Version(s)
Magazine Blocks β Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid 0 <= 1.8.6