CVE-2026-94118
6.5Leap13 · Premium Blocks – Gutenberg Blocks for WordPress
A stored cross-site scripting (XSS) vulnerability exists in the Premium Blocks plugin for WordPress, allowing authenticated contributors to inject malicious scripts into web pages.
Executive summary
The Leap13 Premium Blocks plugin for WordPress contains a cross-site scripting vulnerability that allows authenticated contributors to execute unauthorized scripts, potentially compromising site integrity.
Vulnerability
This vulnerability is a cross-site scripting (XSS) flaw (CWE-79) triggered when an authenticated user with contributor-level privileges injects malicious input that is improperly neutralized during page generation.
Business impact
Successful exploitation of this vulnerability allows an attacker to execute arbitrary JavaScript in the context of a victim's browser session. While the CVSS score of 6.5 reflects a medium severity, the ability for an authenticated contributor to perform actions on behalf of higher-privileged users can lead to unauthorized content modification, administrative account takeover, or the redirection of site traffic to malicious domains.
Remediation
Immediate Action: Update the Premium Blocks – Gutenberg Blocks for WordPress plugin to version 2.3.18 or the latest available release immediately.
Proactive Monitoring: Review WordPress user account activities and audit logs for suspicious script injections or unexpected changes to posts and pages created by contributor-level accounts.
Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to detect and block common XSS attack patterns in HTTP requests.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Organizations utilizing the Premium Blocks plugin should prioritize the update to version 2.3.18 as part of their standard maintenance cycle. Given the potential for XSS to escalate privileges within the WordPress environment, ensuring that all plugins remain patched is essential to maintaining the security of the content management system.
More Leap13 CVEs
History
- Analyst report written