Input validation vulnerability in Blocks 1.6.41

The Blocks plugin for WordPress is vulnerable to a type of malicious attack called Stored Cross-Site Scripting. This vulnerability affects versions up to and including 1.6.41, and happens when the website does not sanitize the input and escape the output properly. This issue can be exploited by attackers with administrator-level permissions, allowing them to inject malicious web scripts into pages that will then execute automatically when a user accesses them. This vulnerability only affects WordPress installations that are set up for multiple sites and those where the ‘unfiltered_html’ feature has been disabled.

Detected in:

Blocks fixed vulnerable versions: >= * <= 1.6.42

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.