CVE-2026-88824
Last modified
CVE-2026-88824 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. The Master Blocks WordPress plugin before 1.5.0 does not have authorisation on one of its REST routes, allowing unauthenticated users to update its settings, including a value that is output unescaped in the admin area, leading to Stored XSS that executes in the session of any administrator visiting a wp-admin page.. EPSS estimates a 0.28% chance of exploitation in the next 30 days.
Description
The Master Blocks WordPress plugin before 1.5.0 does not have authorisation on one of its REST routes, allowing unauthenticated users to update its settings, including a value that is output unescaped in the admin area, leading to Stored XSS that executes in the session of any administrator visiting a wp-admin page.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Unknown | Master Blocks | >= 1.4.1, < 1.5.0 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-88824?
How severe is CVE-2026-88824?
How do I fix CVE-2026-88824?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-88806A malicious X server could exploit a buffer overflow in libX…7.5
- CVE-2026-88807A heap overflow in libXrender before 0.9.13 in RenderQueryPi…8.9
- CVE-2026-8881Version 3.0.7 of the Securly Chrome Extension uses EVP_Bytes…7.5
- CVE-2026-88817An authenticated, non-guest user of Curiosity Workspace coul…8.7
- CVE-2026-88819In Siglet current and past versions the refresh token handle…6.3
- CVE-2026-8882The WP ApplicantStack Jobs Display plugin for WordPress is v…6.4
- CVE-2026-88825The iGMS Direct Booking WordPress plugin before 2.0 does not…8.8
- CVE-2026-8883The Global Body Mass Index Calculator plugin for WordPress i…6.4
- CVE-2026-88830A unit confusion in BusyBox TLS Montgomery reduction buffer …7.5
- CVE-2026-88831BusyBox httpd IP deny rules with invalid CIDR prefix lengths…5.3
- CVE-2026-88832BusyBox romfs volume ID parsing uses unbounded strlen on att…7.3
- CVE-2026-88835BusyBox dpkg read_package_field() steps past a NUL terminato…6.1
Are you affected by CVE-2026-88824?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
