Junglewise Threat Intelligence

CVE-2026-8981: nK Lazy Blocks Stored XSS in block template code fields

CVE-2026-8981 · Severity: info · CVSS 3.5 · Published 2026-06-09

Executive brief

The Lazy Blocks (Custom Block Builder) plugin for WordPress, which allows users to create custom content blocks, contains a security flaw. This vulnerability allows a site administrator—who would normally be restricted from adding custom scripts—to bypass those restrictions and inject malicious code into the website. If exploited, this code would run in the browsers of any visitor who views a page containing the affected block, potentially leading to unauthorized actions or data theft.

Technical details

The Lazy Blocks plugin (formerly Custom Block Builder) before version 4.3.0 is vulnerable to Stored Cross-Site Scripting (XSS) due to inconsistent capability checks. While the plugin's primary editor interface may restrict the 'unfiltered_html' capability, alternative data paths—specifically via XML-RPC and the 'custom_fields' argument—allow writing directly to the 'lazyblocks_code_frontend_html' post meta without proper validation. This allows an authenticated Administrator (who lacks 'unfiltered_html' in multisite or hardened environments) to inject arbitrary JavaScript. The payload executes when any user, including unauthenticated visitors or higher-privileged users, views a page where the malicious block is embedded. The issue is fixed in version 4.3.0.

Affected products

  • nK Lazy Blocks (Custom Block Builder) < 4.3.0

Timeline

  • 2026-05-19: disclosed: Publicly published by WPScan
  • 2026-05-19: advisory
  • 2026-06-09: patched: NVD publication date; fix available in 4.3.0

References