CVE-2026-40804: WordPress aBlocks plugin <= 2.16.0 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kodezen LLC aBlocks ablocks allows Reflected XSS.This issue affects aBlocks: from n/a through 2.16.0.
Affected Software
Event History
Frequently Asked Questions
Which installations should be treated as affected?
aBlocks installations through version 2.16.0 are affected. The available data does not identify an earlier unaffected version.
Does exploitation require an authenticated WordPress account?
No. The CVSS vector lists privileges required as none and attack vector as network, indicating an attacker does not need authenticated access to reach the vulnerable attack surface.
What conditions are needed for exploitation?
User interaction is required. A victim must interact with attacker-controlled content or a crafted request for the reflected XSS condition to be triggered.
What is the expected security impact?
The CVSS vector indicates low confidentiality, integrity, and availability impact, with scope changed. The overall severity is high with a CVSS score of 7.1.