Executive brief
Cozy Blocks is a WordPress plugin used to design websites with custom layouts and templates. A security flaw allows users with basic editing permissions to hide malicious scripts inside page design elements. When other users or visitors view the affected page, these scripts can execute, potentially leading to unauthorized actions or data theft.
Technical details
The Cozy Blocks plugin for WordPress fails to sufficiently sanitize and escape the 'cozyCustomFont' block attribute, leading to a Stored Cross-Site Scripting (XSS) vulnerability. Authenticated attackers with contributor-level permissions or higher can exploit this by injecting arbitrary web scripts into the block's metadata. These scripts execute in the browser of any user who views the compromised page. The vulnerability exists in all versions up to and including 2.2.11. A patch or update should be applied to address the improper neutralization of input during web page generation (CWE-79).
Affected products
- cozythemes Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates <= 2.2.11
Timeline
- 2026-07-24: disclosed
- 2026-07-24: advisory
References
- https://plugins.trac.wordpress.org/browser/cozy-addons/tags/2.2.11/includes/functions.php
- https://plugins.trac.wordpress.org/browser/cozy-addons/tags/2.2.11/includes/functions.php
- https://plugins.trac.wordpress.org/browser/cozy-addons/tags/2.2.11/includes/functions.php
- https://plugins.trac.wordpress.org/browser/cozy-addons/tags/2.2.11/includes/functions.php
- https://plugins.trac.wordpress.org/browser/cozy-addons/tags/2.2.11/includes/functions.php
- https://plugins.trac.wordpress.org/browser/cozy-addons/tags/2.2.11/includes/functions.php
- https://plugins.trac.wordpress.org/browser/cozy-addons/tags/2.2.11/includes/functions.php