Junglewise Threat Intelligence

CVE-2026-3004: Snow Monkey Blocks Stored XSS in data-slick attribute

CVE-2026-3004 · Severity: medium · CVSS 6.4 · Published 2026-05-13

Executive brief

Snow Monkey Blocks is a popular WordPress plugin used to add custom design elements to websites. A security flaw allows users with basic contributor access to embed malicious scripts into website pages. When other visitors or administrators view these pages, the scripts can run automatically, potentially leading to unauthorized actions or data theft.

Technical details

The Snow Monkey Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on the 'data-slick' attribute. This vulnerability exists in all versions up to and including 24.1.11. An authenticated attacker with Contributor-level permissions or higher can inject arbitrary web scripts into the database. Because the 'data-slick' attribute is not properly neutralized, these scripts will execute in the browser of any user who navigates to the compromised page. This is a stored XSS vulnerability (CWE-79) that can be exploited over the network without user interaction beyond visiting the page.

Affected products

  • Snow Monkey Snow Monkey Blocks up to, and including, 24.1.11

Timeline

  • 2026-05-13: disclosed: CVE published by Wordfence/NVD

References