Executive brief
GenerateBlocks, a popular layout and design plugin for WordPress, contains a security flaw that allows users with basic contributor access to inject malicious scripts into website pages. By manipulating how links are generated within the Headline block, an attacker can create links that execute hidden code when clicked by other users, including site administrators. This could lead to unauthorized actions being performed on the site or the theft of sensitive session information.
Technical details
The GenerateBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on the 'linkMetaFieldType' Dynamic Link Attribute within the Headline Block. Authenticated attackers with contributor-level permissions or higher can exploit this by storing a malicious JavaScript payload in their profile description (a field allowed by get_safe_user_meta_keys()) and then prepending 'javascript:' via the vulnerable attribute. This results in a fully attacker-controlled href attribute that executes arbitrary scripts when a user, such as an administrator, clicks the rendered link. The vulnerability is present in all versions up to and including 2.2.1.
Affected products
- edge22 GenerateBlocks up to, and including, 2.2.1
Timeline
- 2026-07-03: advisory: NVD publication date
References
- https://plugins.trac.wordpress.org/browser/generateblocks/tags/2.2.0/includes/blocks/class-headline.php
- https://plugins.trac.wordpress.org/browser/generateblocks/tags/2.2.0/includes/class-dynamic-content.php
- https://plugins.trac.wordpress.org/browser/generateblocks/tags/2.2.0/includes/class-dynamic-tag-security.php
- https://plugins.trac.wordpress.org/browser/generateblocks/tags/2.2.1/includes/blocks/class-headline.php
- https://plugins.trac.wordpress.org/browser/generateblocks/tags/2.2.1/includes/class-dynamic-content.php
- https://plugins.trac.wordpress.org/browser/generateblocks/tags/2.2.1/includes/class-dynamic-tag-security.php
- https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3582036%40generateblocks&new=3582036%40generateblocks&sfp_email=&sfph_mail=