๐Ÿ” CVE Alert

CVE-2026-88824

UNKNOWN 0.0

Master Blocks 1.4.1 - 1.4.1.4 - Unauthenticated Stored XSS via White Label Settings

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Master Blocks WordPress plugin before 1.5.0 does not have authorisation on one of its REST routes, allowing unauthenticated users to update its settings, including a value that is output unescaped in the admin area, leading to Stored XSS that executes in the session of any administrator visiting a wp-admin page.

Vendor unknown
Product master blocks
Published Sep 19, 2026
Stay Ahead of the Next One

Get instant alerts for unknown master blocks

Be the first to know when new unknown vulnerabilities affecting unknown master blocks are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Master Blocks
1.4.1 < 1.5.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/898fda0a-4d27-4def-ae6f-35bf25a8ae8d/

Credits

Enrico Marcolini - Claudio Marchesini - Dottor Marc WPScan