Junglewise Threat Intelligence

CVE-2026-3498: BlockArt Blocks WordPress plugin stored XSS in clientId attribute

CVE-2026-3498 · Severity: medium · CVSS 6.4 · Published 2026-04-11

Vendors: BlockArt.

Executive brief

BlockArt Blocks is a WordPress plugin used to design and build website layouts. A security flaw allows users with 'Author' level permissions or higher to plant malicious scripts into website pages. These scripts will automatically run in the browser of any visitor who views the affected page, potentially leading to unauthorized actions or data theft.

Technical details

The BlockArt Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping of the 'clientId' block attribute. The vulnerability is located in components such as PostTemplate.php and QueryLoop.php. An authenticated attacker with Author-level permissions or higher can exploit this by injecting malicious JavaScript into a block's attributes. Because the payload is stored in the database and rendered without proper neutralization, the script executes in the context of any user (including administrators) who views the compromised page. This can lead to session hijacking or unauthorized administrative actions. The issue is addressed in version 2.3.0.

Affected products

  • BlockArt BlockArt Blocks Up to and including 2.2.15

Timeline

  • 2026-04-10: disclosed: Reported by Wordfence
  • 2026-04-11: advisory
  • 2026-04-24: other: Last modified date in NVD record

References