CVE-2026-15333: Cozy Blocks <= 2.2.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'cozyCustomFont' Block Attribute
The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'cozyCustomFont' Block Attribute in all versions up to, and including, 2.2.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-15333?
CVE-2026-15333 has a severity rating of medium, with a score of 6.4.
How can I fix CVE-2026-15333?
To fix CVE-2026-15333, update the Cozy Blocks plugin to version 2.2.12 or later.
What type of vulnerability is CVE-2026-15333?
CVE-2026-15333 is a stored Cross-Site Scripting (XSS) vulnerability.
Which versions of Cozy Blocks are affected by CVE-2026-15333?
CVE-2026-15333 affects all versions of Cozy Blocks up to and including 2.2.11.
What is the nature of the attack for CVE-2026-15333?
CVE-2026-15333 can be exploited through an authenticated Contributor+ user when using the 'cozyCustomFont' block attribute.