THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-15950 (MEDIUM 6.4) — The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'layoutCircle.alignment' Block Attribute in all versions up to, and including, 2.2.11 due to insufficient inpu

[NVD] CVE-2026-15950 (MEDIUM 6.4) — The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'layoutCircle.alignment' Block Attribute in all versions up to, and including, 2.2.11 due to insufficient inpu

mednvdPublished 2026-08-01

CVE-2026-15950 CVSS: 6.4 MEDIUM Published: 2026-08-01T09:16:59.870

The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'layoutCircle.alignment' Block Attribute in all versions up to, and including, 2.2.11 due to insufficient input sanitization and output escaping. This makes it po

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-15950