Junglewise Threat Intelligence

CVE-2026-39575: Ronald Huereca Custom Query Blocks DOM-Based XSS in post-type-archive-mapping

CVE-2026-39575 · Severity: medium · CVSS 6.5 · Published 2026-04-08

Executive brief

Custom Query Blocks is a WordPress plugin used to create and manage custom content displays. A security vulnerability in this plugin could allow an attacker with basic contributor-level access to inject malicious scripts into the website. If a site administrator or visitor views the affected content, the script could execute, potentially leading to unauthorized actions, data theft, or website defacement.

Technical details

A DOM-based Cross-Site Scripting (XSS) vulnerability exists in the 'post-type-archive-mapping' component of the Ronald Huereca Custom Query Blocks plugin. The flaw stems from improper neutralization of user-supplied input during web page generation. An attacker with 'Contributor' or higher privileges can inject malicious JavaScript payloads that execute in the context of a victim's browser when they interact with the affected page. This is tracked as CVE-2026-39575 and has been addressed in version 5.6.0.

Affected products

  • Ronald Huereca (DLX Plugins) Custom Query Blocks <= 5.5.0

Timeline

  • 2026-01-13: other: Vulnerability reported by researcher Jitlada
  • 2026-02-12: advisory: Patchstack published advisory details
  • 2026-04-08: disclosed: CVE published to NVD
  • 2026-02-12: patched: Version 5.6.0 released to address the issue

References