CVE-2026-94118: WordPress Premium Blocks – Gutenberg Blocks for WordPress plugin <= 2.3.17 - Cross Site Scripting (XSS) vulnerability
Contributor Cross Site Scripting (XSS) in Premium Blocks – Gutenberg Blocks for WordPress <= 2.3.17 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Premium Blocks – Gutenberg Blocksto a version that resolves this vulnerability.Fixed in 2.3.18
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
An attacker needs Contributor-level access to a WordPress site using the affected plugin. The issue is not exploitable by an unauthenticated visitor based on the available information.
Does exploitation require user interaction?
Yes. The CVSS vector indicates user interaction is required, meaning a user must interact with attacker-controlled content for the XSS payload to execute.
What versions are affected?
Premium Blocks – Gutenberg Blocks for WordPress versions 2.3.17 and earlier are affected.
What is the potential impact of a successful exploit?
The CVSS vector indicates low impact to confidentiality, integrity, and availability, with scope changed. Successful XSS may allow attacker-controlled script to act in the context of a user who interacts with the malicious content.