CVE-2026-88824
HIGH
NVD
CVSS Score
8.8
Severity
HIGH
Published
Sep 19, 2026
Vendor
unknown
Description
The Master Blocks WordPress plugin before 1.5.0 does not have authorisation on one of its REST routes, allowing unauthenticated users to update its settings, including a value that is output unescaped in the admin area, leading to Stored XSS that executes in the session of any administrator visiting a wp-admin page.