CVE-2025-26947: WordPress Services Section block plugin <= 1.3.4 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins Services Section block services-section allows Stored XSS.This issue affects Services Section block: from n/a through <= 1.3.4.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-26947?
CVE-2025-26947 has been classified as a medium severity vulnerability due to its potential for Stored Cross-site Scripting (XSS) attacks.
How do I fix CVE-2025-26947?
To fix CVE-2025-26947, update the Services Section block plugin to version 1.3.5 or later.
What impact does CVE-2025-26947 have on my website?
CVE-2025-26947 allows attackers to execute malicious scripts in the context of logged-in users, potentially compromising user data or site integrity.
Is CVE-2025-26947 specifically related to WordPress?
Yes, CVE-2025-26947 specifically affects the Services Section block plugin for WordPress, versions up to and including 1.3.4.
Who is affected by CVE-2025-26947?
Any users or sites utilizing the Services Section block plugin for WordPress version 1.3.4 or earlier are affected by CVE-2025-26947.