Cross-site Scripting Vulnerability in BlockStrap Page Builder by Stiofan
CVE-2026-94632
7.1HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 9 October 2026
What is CVE-2026-94632?
The BlockStrap Page Builder by Stiofan presents a Cross-site Scripting (XSS) vulnerability, allowing attackers to inject malicious scripts into web pages generated by the plugin. This occurs due to improper handling of user input during the web page generation process. As a result, an attacker can execute arbitrary JavaScript code in the context of a user's browser, which may lead to session hijacking, redirection attacks, or the theft of sensitive information. Users of BlockStrap Page Builder versions from n/a to 0.1.58 should take immediate action to mitigate this risk.
Affected Version(s)
BlockStrap Page Builder - Bootstrap Blocks 0 <= 0.1.58