CVE-2026-25438: WordPress Gutenberg Blocks – Unlimited blocks For Gutenberg plugin <= 1.2.8 - Reflected Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeHunk Gutenberg Blocks unlimited-blocks allows Reflected XSS.This issue affects Gutenberg Blocks: from n/a through <= 1.2.8.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-25438?
CVE-2026-25438 is classified as a medium severity reflected Cross Site Scripting (XSS) vulnerability.
How do I fix CVE-2026-25438?
To fix CVE-2026-25438, you should update the ThemeHunk Unlimited Blocks For Gutenberg plugin to version 1.2.9 or later.
What is the impact of CVE-2026-25438?
CVE-2026-25438 allows attackers to execute arbitrary JavaScript code in a user's browser, potentially leading to session hijacking or data theft.
Which WordPress plugin is affected by CVE-2026-25438?
CVE-2026-25438 affects the ThemeHunk Unlimited Blocks For Gutenberg plugin up to version 1.2.8.
Is CVE-2026-25438 a common vulnerability?
CVE-2026-25438 is a specific reflected XSS vulnerability found in a widely used WordPress plugin, making it a concern for many users and developers.