CVE-2025-54708: WordPress B Blocks Plugin <= 2.0.5 - Cross Site Scripting (XSS) Vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins B Blocks allows DOM-Based XSS. This issue affects B Blocks: from n/a through 2.0.5.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins B Blocks b-blocks allows DOM-Based XSS.This issue affects B Blocks: from n/a through <= 2.0.5.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-54708?
CVE-2025-54708 is categorized as a Cross-Site Scripting (XSS) vulnerability, which can lead to potentially severe security risks.
How do I fix CVE-2025-54708?
To fix CVE-2025-54708, update the B Blocks plugin to version 2.0.6 or later, as versions up to 2.0.5 are vulnerable.
What types of attacks can CVE-2025-54708 enable?
CVE-2025-54708 can enable attackers to execute malicious scripts in the context of users' browsers, facilitating data theft or session hijacking.
What versions of B Blocks are affected by CVE-2025-54708?
CVE-2025-54708 affects B Blocks versions up to and including 2.0.5.
Who is the vendor for CVE-2025-54708?
The vendor for CVE-2025-54708 is bPlugins, the developer of the B Blocks plugin.