Master Blocks 1.4.1 - 1.4.1.4 - Unauthenticated Stored XSS via White Label Settings
Summary
| CVE | CVE-2026-88824 |
|---|---|
| State | PUBLISHED |
| Assigner | WPScan |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-19 07:16:33 UTC |
| Updated | 2026-09-19 07:16:33 UTC |
| Description | The Master Blocks WordPress plugin before 1.5.0 does not have authorisation on one of its REST routes, allowing unauthenticated users to update its settings, including a value that is output unescaped in the admin area, leading to Stored XSS that executes in the session of any administrator visiting a wp-admin page. |
Risk And Classification
Problem Types: CWE-79 Cross-Site Scripting (XSS)
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Unknown | Master Blocks | affected 1.4.1 1.5.0 semver | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| wpscan.com/vulnerability/898fda0a-4d27-4def-ae6f-35bf25a8ae8d | [email protected] | wpscan.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Enrico Marcolini - Claudio Marchesini - Dottor Marc (en)
CNA: WPScan (en)
There are currently no legacy QID mappings associated with this CVE.