Executive brief
BlockArt Blocks is a WordPress plugin used to design and build website layouts. A security flaw allows users with 'Author' level permissions or higher to plant malicious scripts into website pages. These scripts will automatically run in the browser of any visitor who views the affected page, potentially leading to unauthorized actions or data theft.
Technical details
The BlockArt Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping of the 'clientId' block attribute. The vulnerability is located in components such as PostTemplate.php and QueryLoop.php. An authenticated attacker with Author-level permissions or higher can exploit this by injecting malicious JavaScript into a block's attributes. Because the payload is stored in the database and rendered without proper neutralization, the script executes in the context of any user (including administrators) who views the compromised page. This can lead to session hijacking or unauthorized administrative actions. The issue is addressed in version 2.3.0.
Affected products
- BlockArt BlockArt Blocks Up to and including 2.2.15
Timeline
- 2026-04-10: disclosed: Reported by Wordfence
- 2026-04-11: advisory
- 2026-04-24: other: Last modified date in NVD record
References
- https://plugins.trac.wordpress.org/browser/blockart-blocks/tags/2.2.15/includes/BlockTypes/PostTemplate.php
- https://plugins.trac.wordpress.org/browser/blockart-blocks/tags/2.2.15/includes/BlockTypes/QueryLoop.php
- https://plugins.trac.wordpress.org/changeset?old_path=%2Fblockart-blocks/tags/2.2.15&new_path=%2Fblockart-blocks/tags/2.3.0
- https://www.wordfence.com/threat-intel/vulnerabilities/id/7d0cb432-785a-4f38-830f-72b95e65aa5a?source=cve