Ad

CVE-2026-88824

NONE EPSS 0.17%
Обновлено 19 сентября 2026
Unknown
Параметр Значение
Уязвимые версии до 1.5.0
Тип уязвимости CWE-79 Cross-Site Scripting (XSS)
Поставщик Unknown
Публичный эксплойт Нет

The Master Blocks WordPress plugin before 1.5.0 does not have authorisation on one of its REST routes, allowing unauthenticated users to update its settings, including a value that is output unescaped in the admin area, leading to Stored XSS that executes in the session of any administrator visiting a wp-admin page.

Тип уязвимости (CWE)

Уязвимые продукты

unknown:master blocks