Executive brief
A vulnerability exists in the Essential Blocks plugin for WordPress, which is used to design and build custom website layouts. An attacker with basic contributor-level access can inject malicious scripts into website pages. These scripts will run automatically in the browser of any visitor who views the affected page, potentially leading to unauthorized actions or data theft.
Technical details
The Essential Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on the 'configurablePrefix' block attribute. This vulnerability allows authenticated attackers with Contributor-level permissions or higher to inject arbitrary web scripts into pages. The malicious payload is stored on the server and executes in the context of a user's browser session when they visit the compromised page. The issue is present in all versions up to and including 6.1.4. Security engineers should ensure the plugin is updated to a version where these attributes are properly sanitized and escaped.
Affected products
- wpdevteam Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns up to, and including, 6.1.4
Timeline
- 2026-06-25: disclosed: CVE published by Wordfence and NVD
References
- https://plugins.trac.wordpress.org/browser/essential-blocks/tags/6.1.4/includes/Blocks/TableOfContents.php
- https://plugins.trac.wordpress.org/browser/essential-blocks/tags/6.1.4/includes/Blocks/TableOfContents.php
- https://plugins.trac.wordpress.org/browser/essential-blocks/tags/6.1.4/src/blocks/table-of-contents/src/frontend.js
- https://www.wordfence.com/threat-intel/vulnerabilities/id/0efe8bbd-c1c9-48ed-adab-34c0ac3da8bf?source=cve