CVE-2025-50041: WordPress Gutenberg Blocks – ACF Blocks Suite plugin <= 2.6.11 - Cross Site Scripting (XSS) Vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Engine Gutenberg Blocks – ACF Blocks Suite acf-blocks allows Stored XSS.This issue affects Gutenberg Blocks – ACF Blocks Suite: from n/a through <= 2.6.11.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Engine Gutenberg Blocks – ACF Blocks Suite allows Stored XSS. This issue affects Gutenberg Blocks – ACF Blocks Suite: from n/a through 2.6.11.
— NVD
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-50041?
CVE-2025-50041 is considered a high severity vulnerability due to the potential for stored cross-site scripting (XSS) attacks.
How do I fix CVE-2025-50041?
To fix CVE-2025-50041, upgrade the WP Engine Gutenberg Blocks – ACF Blocks Suite to version 2.6.12 or later.
What kind of attacks can CVE-2025-50041 facilitate?
CVE-2025-50041 can facilitate stored XSS attacks, allowing attackers to inject malicious scripts into web pages.
Which versions are affected by CVE-2025-50041?
CVE-2025-50041 affects versions of Gutenberg Blocks – ACF Blocks Suite up to and including 2.6.11.
Is CVE-2025-50041 specific to any platforms?
CVE-2025-50041 is specific to the WP Engine and WordPress platforms using the Gutenberg Blocks – ACF Blocks Suite.