CVE-2026-88993 PUBLISHED

All Bootstrap Blocks <= 1.3.31 - Contributor+ Stored XSS via areoi/button type Attribute

Assigner: WPScan
Reserved: 10.09.2026 Published: 18.09.2026 Updated: 18.09.2026

The All Bootstrap Blocks WordPress plugin through 1.3.31 does not properly escape a block attribute before outputting it in HTML tag-name position, allowing users with Contributor-level access and above to inject arbitrary web scripts that execute when the affected content is viewed.

Product Status

Vendor Unknown
Product All Bootstrap Blocks
Versions Default: unknown
  • affected from 0 to 1.3.31 (incl.)

Credits

  • Revanth Hari Narayana Matte finder
  • WPScan coordinator

References

Problem Types

  • CWE-79 Cross-Site Scripting (XSS) CWE