CVE-2026-88824 PUBLISHED

Master Blocks 1.4.1 - 1.4.1.4 - Unauthenticated Stored XSS via White Label Settings

Assigner: WPScan
Reserved: 10.09.2026 Published: 19.09.2026 Updated: 19.09.2026

The Master Blocks WordPress plugin before 1.5.0 does not have authorisation on one of its REST routes, allowing unauthenticated users to update its settings, including a value that is output unescaped in the admin area, leading to Stored XSS that executes in the session of any administrator visiting a wp-admin page.

Product Status

Vendor Unknown
Product Master Blocks
Versions Default: unaffected
  • affected from 1.4.1 to 1.5.0 (excl.)

Credits

  • Enrico Marcolini - Claudio Marchesini - Dottor Marc finder
  • WPScan coordinator

References

Problem Types

  • CWE-79 Cross-Site Scripting (XSS) CWE