CVE-2026-88824
Master Blocks 1.4.1 - 1.4.1.4 - Unauthenticated Stored XSS via White Label Settings
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Master Blocks WordPress plugin before 1.5.0 does not have authorisation on one of its REST routes, allowing unauthenticated users to update its settings, including a value that is output unescaped in the admin area, leading to Stored XSS that executes in the session of any administrator visiting a wp-admin page.
| Vendor | unknown |
| Product | master blocks |
| Published | Sep 19, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown master blocks
Be the first to know when new unknown vulnerabilities affecting unknown master blocks are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Master Blocks
1.4.1 < 1.5.0
References
Credits
Enrico Marcolini - Claudio Marchesini - Dottor Marc WPScan