OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-88824

HIGH · CVSS 8.8 EPSS 0.51%

Source: NVD + CISA KEV + EPSS · Published 2026-09-19 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

The Master Blocks WordPress plugin prior to version 1.5.0 is vulnerable due to a lack of authorization on a REST route, enabling unauthenticated users to modify plugin settings. This flaw can lead to Stored Cross-Site Scripting (XSS), potentially executing malicious scripts in the session of any administrator accessing the wp-admin area. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate the risk of exploitation.

CVE
CVE-2026-88824
Severity
HIGH
CVSS
8.8
EPSS
0.51%
WordPress

Original NVD Description

The Master Blocks WordPress plugin before 1.5.0 does not have authorisation on one of its REST routes, allowing unauthenticated users to update its settings, including a value that is output unescaped in the admin area, leading to Stored XSS that executes in the session of any administrator visiting a wp-admin page.