Executive brief
Cozy Blocks is a popular WordPress plugin providing a page builder with hundreds of design templates and blocks for the WordPress Gutenberg editor. The plugin fails to properly sanitize user input in the cozyHoverEffect block attribute, allowing authenticated contributors and higher-privileged users to inject malicious JavaScript that executes whenever other users view the compromised page. This could lead to account compromise, malware distribution, or defacement of website content.
Technical details
The vulnerability is a Stored Cross-Site Scripting (XSS) flaw in the cozyHoverEffect block attribute affecting Cozy Blocks versions up to 2.2.16. The root cause is insufficient input sanitization and output escaping; the plugin fails to properly escape the boxShadow.color attribute value during rendering. The attack vector requires network access and authenticated user privileges at the contributor level or above. An attacker exploits a double-quote breakout technique to inject event handlers that bypass wp_kses_post sanitization on save, as the payload contains no angle brackets. The injected script persists server-side and executes in the browser context of any user viewing the affected page. A patch is available in versions after 2.2.16.
Affected products
- WordPress.org Cozy Blocks up to and including 2.2.16
Timeline
- 2026-08-25: disclosed