high · CVSS v3 6.8
CVE-2026-88993
The All Bootstrap Blocks WordPress plugin through 1.3.31 does not properly escape a block attribute before outputting it…
Description
The All Bootstrap Blocks WordPress plugin through 1.3.31 does not properly escape a block attribute before outputting it in HTML tag-name position, allowing users with Contributor-level access and above to inject arbitrary web scripts that execute when the affected content is viewed.
Scores
- Severity
- high
- CVSS v2
- 8.3
- CVSS v3
- 6.8
- CVSS v4
- —
- EPSS
- —