Executive brief
Custom Query Blocks is a WordPress plugin used to create and manage custom content displays. A security vulnerability in this plugin could allow an attacker with basic contributor-level access to inject malicious scripts into the website. If a site administrator or visitor views the affected content, the script could execute, potentially leading to unauthorized actions, data theft, or website defacement.
Technical details
A DOM-based Cross-Site Scripting (XSS) vulnerability exists in the 'post-type-archive-mapping' component of the Ronald Huereca Custom Query Blocks plugin. The flaw stems from improper neutralization of user-supplied input during web page generation. An attacker with 'Contributor' or higher privileges can inject malicious JavaScript payloads that execute in the context of a victim's browser when they interact with the affected page. This is tracked as CVE-2026-39575 and has been addressed in version 5.6.0.
Affected products
- Ronald Huereca (DLX Plugins) Custom Query Blocks <= 5.5.0
Timeline
- 2026-01-13: other: Vulnerability reported by researcher Jitlada
- 2026-02-12: advisory: Patchstack published advisory details
- 2026-04-08: disclosed: CVE published to NVD
- 2026-02-12: patched: Version 5.6.0 released to address the issue