CVE-2026-88824: Master Blocks 1.4.1 - 1.4.1.4 - Unauthenticated Stored XSS via White Label Settings

Published Sep 19, 2026
·
Updated

The Master Blocks WordPress plugin before 1.5.0 does not have authorisation on one of its REST routes, allowing unauthenticated users to update its settings, including a value that is output unescaped in the admin area, leading to Stored XSS that executes in the session of any administrator visiting a wp-admin page.

Affected Software

1 affected component
WordPress Master Blocks<1.5.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade wordpress/Master Blocks to a version that resolves this vulnerability.

    Fixed in 1.5.0
  2. Compensating control

    Restrict access to the Master Blocks REST route used to update White Label settings so unauthenticated users cannot modify it (e.g., enforce authentication at the route or block/deny unauthenticated requests at a reverse proxy/WAF).

Event History

Sep 19, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness

Frequently Asked Questions

1

Who can exploit this issue, and whose session is at risk?

An unauthenticated user can exploit the affected REST route without needing a WordPress account. The stored script executes in the session of an administrator who visits a wp-admin page.

2

Which versions are affected?

Master Blocks versions before 1.5.0 are affected. The reported affected range includes versions 1.4.1 through 1.4.1.4.

3

What setting is involved in the attack?

The vulnerable REST route allows unauthenticated updates to plugin settings, including a White Label Settings value that is later output without escaping in the WordPress administration area.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203