Stored XSS Vulnerability in Master Blocks WordPress Plugin
CVE-2026-88824

Currently unrated

Key Information:

Vendor

WordPress

Vendor
CVE Published:
19 September 2026

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2026-88824?

The Master Blocks plugin for WordPress, prior to version 1.5.0, is vulnerable due to insufficient authorization on certain REST routes. This oversight permits unauthenticated users to modify plugin settings, including values displayed unescaped in the WordPress admin area. Consequently, this leads to a stored XSS vulnerability that can execute malicious scripts in the context of any administrator accessing wp-admin pages. It is crucial for users of the Master Blocks plugin to update to the latest version to mitigate potential risks and secure their WordPress installations.

Affected Version(s)

Master Blocks 1.4.1 < 1.5.0

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Enrico Marcolini - Claudio Marchesini - Dottor Marc
WPScan
.