CVE-2026-88824: Unknown Master Blocks
High severity, CVSS 8.8. EPSS: 0.5% chance of exploitation in the next 30 days.
The Master Blocks WordPress plugin before 1.5.0 does not have authorisation on one of its REST routes, allowing unauthenticated users to update its settings, including a value that is output unescaped in the admin area, leading to Stored XSS that executes in the session of any administrator visiting a wp-admin page.
Affected products
- Unknown Master Blocks: from 1.4.1, before 1.5.0 (fixed in 1.5.0)
Published 2026-09-19. Last modified 2026-09-21.