Stored XSS Vulnerability in Master Blocks WordPress Plugin
CVE-2026-88824
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 19 September 2026
Badges
What is CVE-2026-88824?
The Master Blocks plugin for WordPress, prior to version 1.5.0, is vulnerable due to insufficient authorization on certain REST routes. This oversight permits unauthenticated users to modify plugin settings, including values displayed unescaped in the WordPress admin area. Consequently, this leads to a stored XSS vulnerability that can execute malicious scripts in the context of any administrator accessing wp-admin pages. It is crucial for users of the Master Blocks plugin to update to the latest version to mitigate potential risks and secure their WordPress installations.
Affected Version(s)
Master Blocks 1.4.1 < 1.5.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.