CVE-2026-78290: WordPress Magazine Blocks plugin <= 1.8.6 - Cross Site Scripting (XSS) vulnerability
Published Aug 24, 2026
·Updated
Contributor Cross Site Scripting (XSS) in Magazine Blocks <= 1.8.6 versions.
Affected Software
1 affected component
WordPress Magazine Blocks<=1.8.6
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Magazine Blocks Pluginto a version that resolves this vulnerability.Fixed in 1.8.7
Event History
Aug 24, 2026
CVE Published
via MITRE·11:39 AM
Data Sourced
via MITRE·11:39 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Which users can exploit this issue?
The vulnerability is described as contributor XSS, indicating that an attacker needs Contributor-level access to the WordPress site.
2
Is administrator interaction required for exploitation?
Yes. The CVSS vector includes UI:R, meaning exploitation requires user interaction. The provided data does not specify what action the victim must take.
3
What security impact can successful exploitation have?
Successful exploitation can affect confidentiality, integrity, and availability at a low impact level, and the impact scope is changed (S:C) according to the supplied CVSS vector.