Sceawere
Vulnerability Detail
CVE-2026-94632UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Reflected XSS in BlockStrap Builder
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.1
- Creation Date
- 3h ago
- Vendor
- Stiofan
- Product
- BlockStrap Page Builder - Bootstrap Blocks
- Attack Type
- Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Stiofan BlockStrap Page Builder - Bootstrap Blocks blockstrap-page-builder-blocks allows Reflected XSS.This issue affects BlockStrap Page Builder - Bootstrap Blocks: from n/a through 0.1.58.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.1",
"pubDate": "2026-10-09T10:16:40.880Z",
"pubdate": "2026-10-09T10:16:40.880Z",
"executiveSummary": "Stiofan BlockStrap Page Builder - Bootstrap Blocks versions n/a through 0.1.58 are vulnerable to a Reflected Cross-Site Scripting (XSS) vulnerability.\nThis flaw arises from improper neutralization of user-supplied input during web page generation, allowing an attacker to inject and execute arbitrary JavaScript in the context of a victim's browser session.\nThe vulnerability poses a significant risk to affected systems, as successful exploitation enables attackers to steal sensitive session cookies, perform unauthorized actions on behalf of authenticated users, or redirect users to malicious domains.\nThe attack vector is typically facilitated through manipulated URLs or input parameters that the application reflects back to the user without adequate sanitization or output encoding.\nNo specific authentication is required to trigger this vulnerability, making it accessible to unauthenticated attackers, provided they can persuade a victim to interact with a crafted malicious link.\nOrganizations using this plugin should prioritize updating to a version that addresses the vulnerability or implement strict input validation and output encoding mechanisms.",
"technicalDetails": "The vulnerability is classified as CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').\nThe root cause of this vulnerability lies in the failure of the Stiofan BlockStrap Page Builder - Bootstrap Blocks plugin to perform adequate context-aware output encoding on user-supplied parameters before reflecting them into the HTML response.\nIn a reflected XSS scenario, the malicious payload is part of the request sent to the web server, typically embedded within a URL parameter or query string. When the application processes this request, it dynamically generates a response page that includes the unsanitized input.\nIf the application does not utilize appropriate security headers or encoding functions (such as esc_html(), esc_js(), or esc_url() in the WordPress context), the browser interprets the injected data as legitimate executable script content rather than inert text.\nThe attack flow proceeds as follows: First, an attacker identifies an entry point within the plugin's functionality that reflects input to the browser. Second, the attacker crafts a malicious URI containing a JavaScript payload (e.g., <script>alert('XSS')</script>) injected into the vulnerable parameter. Third, the attacker distributes this link to a target user. When the authenticated user clicks the link, the server processes the request and sends back a response containing the script. The user's browser, observing the script, executes it within the origin of the vulnerable application.\nSince the payload executes within the victim's session, the attacker can bypass Same-Origin Policy (SOP) restrictions to perform actions such as extracting session identifiers (PHPSESSID/Auth Cookies), capturing sensitive form data, or modifying the Document Object Model (DOM) to display phishing interfaces.\nThe affected component involves the block rendering or parameter handling logic within the BlockStrap Page Builder codebase that processes user input before rendering blocks. Because the reflection happens server-side during the document generation phase, the browser is forced to parse and execute the payload as the page loads.\nGiven that this vulnerability affects versions 0.1.58 and below, all deployments are at risk of arbitrary script execution. The vulnerability is network-accessible, and because it relies on the browser's interpretation of the injected payload, the attack impact remains high regardless of whether the victim is an administrator or a standard user."
}