Executive brief
The Post Blocks & Tools plugin for WordPress, which provides custom layout blocks for website content, contains a security flaw in its Posts Slider block. This vulnerability allows users with author-level permissions to embed malicious scripts into website pages. When other visitors or administrators view these pages, the scripts can execute, potentially leading to unauthorized actions or the theft of sensitive session information.
Technical details
The Post Blocks & Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on the 'sliderStyle' attribute within the Posts Slider block. An authenticated attacker with Author-level privileges or higher can inject arbitrary JavaScript into the block configuration. Because the input is stored in the database and rendered without proper escaping, the script executes in the context of any user's browser who views the affected page. This can lead to session hijacking or unauthorized administrative actions. The issue is fixed in version 1.3.1.
Affected products
- pubudu-malalasekara Post Blocks & Tools up to, and including, 1.3.0
Timeline
- 2026-04-08: disclosed
- 2026-04-08: advisory
References
- https://plugins.trac.wordpress.org/browser/bnm-blocks/tags/1.3.0/src/blocks/posts/slider/view.php
- https://plugins.trac.wordpress.org/browser/bnm-blocks/tags/1.3.1/src/blocks/posts/slider/view.php
- https://plugins.trac.wordpress.org/browser/bnm-blocks/trunk/src/blocks/posts/slider/view.php
- https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3500959%40bnm-blocks%2Ftrunk&old=3456918%40bnm-blocks%2Ftrunk&sfp_email=&sfph_mail=
- https://www.wordfence.com/threat-intel/vulnerabilities/id/aeada6dc-0851-45e8-ada9-ff0427b7f17a?source=cve