CVE-2025-32173: WordPress B Blocks plugin <= 2.0.0 - Stored Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins B Blocks b-blocks allows Stored XSS.This issue affects B Blocks: from n/a through <= 2.0.0.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-32173?
CVE-2025-32173 is classified as a high severity vulnerability due to its potential to allow stored cross-site scripting (XSS) attacks.
How do I fix CVE-2025-32173?
To fix CVE-2025-32173, update the B Blocks - The ultimate block collection plugin to version 2.0.1 or later.
What types of applications are affected by CVE-2025-32173?
CVE-2025-32173 affects the B Blocks - The ultimate block collection plugin used in WordPress applications.
What kind of attack can be executed using CVE-2025-32173?
CVE-2025-32173 allows attackers to execute stored cross-site scripting (XSS) attacks, potentially compromising web application integrity.
Is CVE-2025-32173 easily exploitable?
Yes, CVE-2025-32173 is considered easily exploitable, as it allows an attacker to inject malicious scripts that execute in the browsers of users visiting the affected site.