Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-88993

Опубликовано: 18 сент. 2026
Источник: nvd
CVSS3: 6.8
EPSS Низкий

Описание

The All Bootstrap Blocks WordPress plugin through 1.3.31 does not properly escape a block attribute before outputting it in HTML tag-name position, allowing users with Contributor-level access and above to inject arbitrary web scripts that execute when the affected content is viewed.

EPSS

Процентиль: 15%
0.00235
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.8
github
5 дней назад

The All Bootstrap Blocks WordPress plugin through 1.3.31 does not properly escape a block attribute before outputting it in HTML tag-name position, allowing users with Contributor-level access and above to inject arbitrary web scripts that execute when the affected content is viewed.

EPSS

Процентиль: 15%
0.00235
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-79