CVE-2026-104400: WordPress B Blocks plugin <= 2.1.8 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins B Blocks b-blocks allows Stored XSS.This issue affects B Blocks: from n/a through 2.1.8.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress B Blocksto a version that resolves this vulnerability.Fixed in 2.1.9
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs at least low-level privileges and must be able to induce a user to interact with the malicious content. The issue is remotely reachable and has low attack complexity.
Which versions are affected?
B Blocks versions through 2.1.8 are affected. The available data does not identify a fixed version.
What is the potential impact?
This is a stored XSS issue. Successful exploitation can affect confidentiality, integrity, and availability at low impact, with scope changed.