Junglewise Threat Intelligence

CVE-2026-57650: BlockArt Magazine Blocks Contributor XSS

CVE-2026-57650 · Severity: medium · CVSS 6.5 · Published 2026-06-26

Technologies: BlockArt Magazine Blocks. Vendors: BlockArt.

Executive brief

Magazine Blocks is a WordPress plugin used to create layout sections for digital magazines and news sites. A security flaw allows users with 'Contributor' level access to inject malicious scripts into website pages. If a site administrator or visitor views the affected content, these scripts could redirect users to malicious sites, display unauthorized advertisements, or compromise the viewer's session.

Technical details

A Stored Cross-Site Scripting (XSS) vulnerability exists in the Magazine Blocks plugin for WordPress due to improper neutralization of input during web page generation (CWE-79). The flaw allows authenticated attackers with 'Contributor' level permissions or higher to inject arbitrary web scripts into pages. These scripts execute in the context of a victim's browser when they visit the affected page, requiring some user interaction (viewing the crafted content). The vulnerability is addressed in version 1.8.4.

Affected products

  • BlockArt Magazine Blocks <= 1.8.3

Timeline

  • 2026-02-06: other: Reported by Jarno Vos
  • 2026-06-26: disclosed: Early warning sent to Patchstack customers
  • 2026-06-26: advisory: Public advisory published by Patchstack and NVD
  • 2026-06-26: patched: Version 1.8.4 released to address the vulnerability

References