What is CVE-2026-13458?
CVE-2026-13458 is a Stored Cross-Site Scripting (XSS) vulnerability in the GenerateBlocks plugin for WordPress. It affects versions up to and including 2.3.0, allowing authenticated attackers to inject arbitrary web scripts via Dynamic Tag Injection in HTML Attributes due to insufficient sanitization. Updating the plugin to the latest version is strongly recommended.
Azərbaycanca: CVE-2026-13458, WordPress GenerateBlocks plaginindəki Stored Cross-Site Scripting (Saxlanılan Saytlararası Skript) zəifliyidir. 2.3.0 və əvvəlki versiyalara təsir edən bu zəiflik, təsdiqlənmiş istifadəçilərə HTML atributlarında Dinamik Teq İnyeksiyası vasitəsilə zərərli skript yerləşdirməyə imkan verir. Plagini son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which versions of the GenerateBlocks plugin are vulnerable to CVE-2026-13458?
The CVE-2026-13458 vulnerability affects versions up to and including 2.3.0 of the GenerateBlocks plugin.
What can attackers achieve by exploiting CVE-2026-13458?
Authenticated attackers can inject arbitrary web scripts via Dynamic Tag Injection in HTML Attributes.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.