Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-88824

HIGH NVD
CVSS Score 8.8
Severity HIGH
Published Sep 19, 2026
Vendor unknown

Description

The Master Blocks WordPress plugin before 1.5.0 does not have authorisation on one of its REST routes, allowing unauthenticated users to update its settings, including a value that is output unescaped in the admin area, leading to Stored XSS that executes in the session of any administrator visiting a wp-admin page.

References