๐Ÿ” CVE Alert

CVE-2026-88993

UNKNOWN 0.0

All Bootstrap Blocks <= 1.3.31 - Contributor+ Stored XSS via areoi/button type Attribute

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The All Bootstrap Blocks WordPress plugin through 1.3.31 does not properly escape a block attribute before outputting it in HTML tag-name position, allowing users with Contributor-level access and above to inject arbitrary web scripts that execute when the affected content is viewed.

Vendor unknown
Product all bootstrap blocks
Published Sep 18, 2026
Stay Ahead of the Next One

Get instant alerts for unknown all bootstrap blocks

Be the first to know when new unknown vulnerabilities affecting unknown all bootstrap blocks are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / All Bootstrap Blocks
0 โ‰ค 1.3.31

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/fc1f2f62-62cd-4a70-b541-2278eb0edefe/

Credits

Revanth Hari Narayana Matte WPScan