CVE-2026-88824

NONE EPSS 0.17%
Updated Sep 19, 2026
Unknown
Parameter Value
Affected Versions before 1.5.0
Type CWE-79 Cross-Site Scripting (XSS)
Vendor Unknown
Public PoC No

The Master Blocks WordPress plugin before 1.5.0 does not have authorisation on one of its REST routes, allowing unauthenticated users to update its settings, including a value that is output unescaped in the admin area, leading to Stored XSS that executes in the session of any administrator visiting a wp-admin page.

Vulnerable Products

unknown:master blocks