Sceawere
Vulnerability Detail
CVE-2026-104400UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Stored XSS in B Blocks
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.5
- Creation Date
- 10h ago
- Vendor
- bPlugins
- Product
- B Blocks
- Attack Type
- Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins B Blocks b-blocks allows Stored XSS.This issue affects B Blocks: from n/a through 2.1.8.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.5",
"pubDate": "2026-10-05T09:17:08.067Z",
"pubdate": "2026-10-05T09:17:08.067Z",
"executiveSummary": "The bPlugins B Blocks plugin for WordPress is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability. The flaw originates from the improper neutralization of user-supplied input during web page generation, specifically within the plugin's data handling mechanisms.\nThis vulnerability allows an authenticated attacker to inject malicious JavaScript payloads into the WordPress database via the affected plugin's interface. Once stored, these payloads are executed in the browser of any user who views the rendered page containing the injected content, including administrators.\nThe impact of this vulnerability is significant, as it facilitates unauthorized actions on behalf of the victim, such as session hijacking, unauthorized data exfiltration, or the defacement of the affected website. The risk is heightened if the victim possesses elevated privileges, potentially leading to a full site compromise. Successful exploitation requires an attacker to have sufficient permissions to interact with the plugin's input fields, as no specific network exposure beyond the standard WordPress administrative interface is typically required. Remediation necessitates updating the plugin to a patched version once available or implementing strict input sanitization and output encoding policies.",
"technicalDetails": "The vulnerability is classified as CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'). It affects B Blocks versions from n/a through 2.1.8.\nRoot Cause Analysis: The core issue resides in the plugin's failure to adequately sanitize or escape input provided by users before storing it in the WordPress database and subsequently rendering it within the administrative or front-end components of the site. When the plugin processes input—likely via a module configuration or content block setting—it fails to filter out executable script tags or malicious event handlers.\nAttack Flow and Exploitation: The exploitation process begins when an attacker accesses the B Blocks configuration interface. By inputting a crafted payload (e.g., <script>alert('XSS')</script> or an image tag with an 'onerror' attribute) into an input field susceptible to storage, the attacker triggers an HTTP POST request that transmits the script to the server. The plugin saves this raw input into the WordPress 'wp_options' table or a custom database table associated with the plugin.\nPayload Execution: Once stored, the payload is persisted. Whenever an administrator or a privileged user navigates to the administrative page where B Blocks renders this data, the browser interprets the stored string as active content rather than plain text. Because the application fails to utilize context-aware output encoding (such as esc_html() or esc_js() functions in the WordPress ecosystem), the browser executes the injected JavaScript code in the context of the user's active session.\nPost-Exploitation: The executed script runs with the permissions of the victim. If an administrator visits the affected page, the script could perform unauthorized administrative tasks, such as creating a new rogue administrator account, modifying plugin settings to maintain persistence, or redirecting the user to a malicious external site. Furthermore, the attacker can leverage the victim's session cookies to bypass authentication mechanisms, provided the 'HttpOnly' flag is not strictly enforced on sensitive cookies.\nNetwork Exposure: The vulnerability is exploitable via the standard web interface. Authentication is required to interact with the plugin's input vectors, meaning the threat profile is primarily associated with compromised accounts or malicious actors with administrative or contributor-level access to the WordPress dashboard."
}