Cross-site Scripting Vulnerability in BlockStrap Page Builder by Stiofan
CVE-2026-94632

7.1HIGH

What is CVE-2026-94632?

The BlockStrap Page Builder by Stiofan presents a Cross-site Scripting (XSS) vulnerability, allowing attackers to inject malicious scripts into web pages generated by the plugin. This occurs due to improper handling of user input during the web page generation process. As a result, an attacker can execute arbitrary JavaScript code in the context of a user's browser, which may lead to session hijacking, redirection attacks, or the theft of sensitive information. Users of BlockStrap Page Builder versions from n/a to 0.1.58 should take immediate action to mitigate this risk.

Affected Version(s)

BlockStrap Page Builder - Bootstrap Blocks 0 <= 0.1.58

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nguyen Viet Tin | Patchstack Bug Bounty Program
.