Junglewise Threat Intelligence

CVE-2026-15334: CozyThemes Cozy Blocks Stored XSS in icon.view attribute

CVE-2026-15334 · Severity: medium · CVSS 6.4 · Published 2026-07-24

Executive brief

Cozy Blocks is a WordPress plugin used to design website layouts and pages. A security flaw allows users with basic contributor permissions to embed malicious scripts into website pages. When other users or administrators visit these pages, the scripts execute automatically, which could lead to unauthorized actions or data theft.

Technical details

The Cozy Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on the 'icon.view' block attribute within the Advanced Categories component. An authenticated attacker with contributor-level permissions or higher can inject arbitrary web scripts into a page's block attributes. Because the plugin fails to properly neutralize this input before rendering it on the front end, the script executes in the context of any user's session who views the compromised page. This vulnerability is present in all versions up to and including 2.2.11.

Affected products

  • cozythemes Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates <= 2.2.11

Timeline

  • 2026-07-24: disclosed
  • 2026-07-24: advisory

References

Related threats