WordPress Plugin Vulnerabilities
Lazy Blocks < 4.3.0 - Admin+ Stored XSS via Custom Block Frontend HTML
Description
The plugin does not consistently check the unfiltered_html capability across all paths that write to its block template code fields, allowing administrators on multisite installations (or single-site installs with DISALLOW_UNFILTERED_HTML defined) to inject arbitrary JavaScript that executes for any visitor of pages embedding the affected block.
Proof of Concept
Affects Plugins
References
CVE
Classification
Type
XSS
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
Luca Jungnickel
Submitter
Luca Jungnickel
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2026-05-19 (about 21 days ago)
Added
2026-05-19 (about 20 days ago)
Last Updated
2026-05-19 (about 20 days ago)