Executive brief
The Lazy Blocks (Custom Block Builder) plugin for WordPress, which allows users to create custom content blocks, contains a security flaw. This vulnerability allows a site administrator—who would normally be restricted from adding custom scripts—to bypass those restrictions and inject malicious code into the website. If exploited, this code would run in the browsers of any visitor who views a page containing the affected block, potentially leading to unauthorized actions or data theft.
Technical details
The Lazy Blocks plugin (formerly Custom Block Builder) before version 4.3.0 is vulnerable to Stored Cross-Site Scripting (XSS) due to inconsistent capability checks. While the plugin's primary editor interface may restrict the 'unfiltered_html' capability, alternative data paths—specifically via XML-RPC and the 'custom_fields' argument—allow writing directly to the 'lazyblocks_code_frontend_html' post meta without proper validation. This allows an authenticated Administrator (who lacks 'unfiltered_html' in multisite or hardened environments) to inject arbitrary JavaScript. The payload executes when any user, including unauthenticated visitors or higher-privileged users, views a page where the malicious block is embedded. The issue is fixed in version 4.3.0.
Affected products
- nK Lazy Blocks (Custom Block Builder) < 4.3.0
Timeline
- 2026-05-19: disclosed: Publicly published by WPScan
- 2026-05-19: advisory
- 2026-06-09: patched: NVD publication date; fix available in 4.3.0