Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
6.5
CoBlocks allows Malicious Code to Run on Websites
CVE-2026-27094
Summary
CoBlocks, a plugin for creating custom WordPress blocks, contains a security flaw that allows hackers to inject malicious code into websites using the plugin. This means that if a hacker can trick a website administrator into using a specially crafted block, they can execute malicious code on the site, potentially stealing data or taking control of the site. Website owners using CoBlocks should update to the latest version to fix this issue.
Original title
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GoDaddy CoBlocks coblocks allows Stored XSS.This issue affects CoBlocks: from n/a through <= 3....
Original description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GoDaddy CoBlocks coblocks allows Stored XSS.This issue affects CoBlocks: from n/a through <= 3.1.16.
nvd CVSS3.1
6.5
Vulnerability type
CWE-79
Cross-site Scripting (XSS)
Published: 19 Feb 2026 · Updated: 11 Mar 2026 · First seen: 6 Mar 2026