First published: Thu Jan 09 2025(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CBB Team Content Blocks Builder allows Stored XSS.This issue affects Content Blocks Builder: from n/a through 2.7.6.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
CBB Team Content Blocks Builder | <=2.7.6 | |
WordPress Content Blocks Builder | <=2.7.6 |
Update the WordPress Content Blocks Builder wordpress plugin to the latest available version (at least 2.7.7).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-22810 has been rated with a high severity due to its potential for Stored Cross-site Scripting (XSS) attacks.
To mitigate CVE-2025-22810, update the CBB Team Content Blocks Builder plugin to the latest version beyond 2.7.6.
CVE-2025-22810 affects the CBB Team Content Blocks Builder versions up to and including 2.7.6.
CVE-2025-22810 is an improper neutralization of input vulnerability leading to Stored Cross-site Scripting (XSS).
Currently, the only effective workaround for CVE-2025-22810 is to update the vulnerable plugin to a secure version.