CVE-2026-27094: WordPress CoBlocks plugin <= 3.1.16 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GoDaddy CoBlocks coblocks allows Stored XSS.This issue affects CoBlocks: from n/a through <= 3.1.16.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-27094?
CVE-2026-27094 is classified as a medium severity Cross Site Scripting (XSS) vulnerability affecting the GoDaddy CoBlocks plugin.
How do I fix CVE-2026-27094?
To fix CVE-2026-27094, update the GoDaddy CoBlocks plugin to a version newer than 3.1.16.
What is the impact of CVE-2026-27094?
The impact of CVE-2026-27094 allows for stored XSS, which could enable attackers to execute malicious scripts in users' browsers.
Which versions are vulnerable to CVE-2026-27094?
Versions of the GoDaddy CoBlocks plugin from n/a up to and including 3.1.16 are vulnerable to CVE-2026-27094.
Is CVE-2026-27094 a common vulnerability?
CVE-2026-27094 is a specific vulnerability tied to the GoDaddy CoBlocks plugin, which may be common among users of that plugin.