Cross-Site Scripting Flaw in All Bootstrap Blocks Plugin for WordPress
CVE-2026-88993
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 18 September 2026
Badges
What is CVE-2026-88993?
The All Bootstrap Blocks WordPress plugin prior to version 1.3.31 contains a vulnerability where it fails to adequately escape a block attribute before rendering it in an HTML tag-name context. This security oversight permits users with Contributor-level access and higher to inject malicious web scripts. Such scripts can execute when users view the affected content, potentially compromising site security and user data. This type of vulnerability underscores the importance of implementing proper input validation and output escaping in web applications.
Affected Version(s)
All Bootstrap Blocks 0 <= 1.3.31
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.