WordPress Plugin Vulnerabilities

Lazy Blocks < 4.3.0 - Admin+ Stored XSS via Custom Block Frontend HTML

Description

The plugin does not consistently check the unfiltered_html capability across all paths that write to its block template code fields, allowing administrators on multisite installations (or single-site installs with DISALLOW_UNFILTERED_HTML defined) to inject arbitrary JavaScript that executes for any visitor of pages embedding the affected block.

Proof of Concept

Affects Plugins

Fixed in 4.3.0

References

Classification

Type
XSS
CWE
CVSS

Miscellaneous

Original Researcher
Luca Jungnickel
Submitter
Luca Jungnickel
Verified
Yes

Timeline

Publicly Published
2026-05-19 (about 21 days ago)
Added
2026-05-19 (about 20 days ago)
Last Updated
2026-05-19 (about 20 days ago)

Other