Junglewise Threat Intelligence

CVE-2026-15393: Cozythemes Cozy Blocks Stored XSS in postMeta.font.size attribute

CVE-2026-15393 · Severity: medium · CVSS 6.4 · Published 2026-07-28

Executive brief

The Cozy Blocks plugin for WordPress, which provides design templates and blocks for website building, contains a security flaw. This vulnerability allows users with basic contributor permissions to embed malicious scripts into website pages. When other visitors or administrators view these pages, the scripts execute, potentially leading to unauthorized actions or data theft.

Technical details

The Cozy Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on the 'postMeta.font.size' block attribute. The flaw exists in versions up to and including 2.2.11. An authenticated attacker with contributor-level permissions or higher can inject malicious JavaScript into a post or page via this attribute. Because the script is stored on the server, it will execute in the browser context of any user (including administrators) who views the compromised content. This can lead to session hijacking or unauthorized administrative actions.

Affected products

  • cozythemes Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates <= 2.2.11

Timeline

  • 2026-07-28: disclosed: Initial publication of the CVE record
  • 2026-07-28: advisory

References

Related threats