CVE-2026-78264: WordPress Toolset Blocks plugin <= 1.6.26 - Cross Site Scripting (XSS) vulnerability
Published Aug 24, 2026
·Updated
Unauthenticated Cross Site Scripting (XSS) in Toolset Blocks <= 1.6.26 versions.
Affected Software
1 affected component
WordPress Toolset Blocks<=1.6.26
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Toolset Blocks Pluginto a version that resolves this vulnerability.Fixed in 1.6.27
Event History
Aug 24, 2026
CVE Published
via MITRE·09:31 PM
Data Sourced
via MITRE·09:31 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·10:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What access does an attacker need to exploit this issue?
No authentication or prior privileges are required. Exploitation does require user interaction, as reflected by the UI:R vector.
2
What versions are affected?
Toolset Blocks versions 1.6.26 and earlier are affected. The provided information does not identify a fixed version.
3
What is the potential impact of successful exploitation?
The vulnerability is rated high with a 7.1 CVSS score. Its vector indicates low confidentiality, integrity, and availability impact, with scope changed.