CVE-2026-94118

6.5

Leap13 · Premium Blocks – Gutenberg Blocks for WordPress

A stored cross-site scripting (XSS) vulnerability exists in the Premium Blocks plugin for WordPress, allowing authenticated contributors to inject malicious scripts into web pages.

Executive summary

The Leap13 Premium Blocks plugin for WordPress contains a cross-site scripting vulnerability that allows authenticated contributors to execute unauthorized scripts, potentially compromising site integrity.

Vulnerability

This vulnerability is a cross-site scripting (XSS) flaw (CWE-79) triggered when an authenticated user with contributor-level privileges injects malicious input that is improperly neutralized during page generation.

Business impact

Successful exploitation of this vulnerability allows an attacker to execute arbitrary JavaScript in the context of a victim's browser session. While the CVSS score of 6.5 reflects a medium severity, the ability for an authenticated contributor to perform actions on behalf of higher-privileged users can lead to unauthorized content modification, administrative account takeover, or the redirection of site traffic to malicious domains.

Remediation

Immediate Action: Update the Premium Blocks – Gutenberg Blocks for WordPress plugin to version 2.3.18 or the latest available release immediately.

Proactive Monitoring: Review WordPress user account activities and audit logs for suspicious script injections or unexpected changes to posts and pages created by contributor-level accounts.

Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to detect and block common XSS attack patterns in HTTP requests.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Organizations utilizing the Premium Blocks plugin should prioritize the update to version 2.3.18 as part of their standard maintenance cycle. Given the potential for XSS to escalate privileges within the WordPress environment, ensuring that all plugins remain patched is essential to maintaining the security of the content management system.

More Leap13 CVEs

History

  1. Analyst report written