Executive brief
Cozy Blocks is a WordPress plugin used to design website layouts and pages. A security flaw allows users with basic contributor permissions to embed malicious scripts into website pages. When other users or administrators visit these pages, the scripts execute automatically, which could lead to unauthorized actions or data theft.
Technical details
The Cozy Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on the 'icon.view' block attribute within the Advanced Categories component. An authenticated attacker with contributor-level permissions or higher can inject arbitrary web scripts into a page's block attributes. Because the plugin fails to properly neutralize this input before rendering it on the front end, the script executes in the context of any user's session who views the compromised page. This vulnerability is present in all versions up to and including 2.2.11.
Affected products
- cozythemes Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates <= 2.2.11
Timeline
- 2026-07-24: disclosed
- 2026-07-24: advisory
References
- https://plugins.trac.wordpress.org/browser/cozy-addons/tags/2.2.11/blocks/advanced-categories/block.json
- https://plugins.trac.wordpress.org/browser/cozy-addons/tags/2.2.11/blocks/advanced-categories/render.php
- https://plugins.trac.wordpress.org/browser/cozy-addons/tags/2.2.11/blocks/advanced-categories/render.php
- https://plugins.trac.wordpress.org/browser/cozy-addons/tags/2.2.11/blocks/advanced-categories/render.php
- https://plugins.trac.wordpress.org/browser/cozy-addons/tags/2.2.11/blocks/advanced-categories/render.php
- https://plugins.trac.wordpress.org/browser/cozy-addons/tags/2.2.11/blocks/advanced-categories/render.php
- https://plugins.trac.wordpress.org/browser/cozy-addons/tags/2.2.9/blocks/advanced-categories/block.json