What the vulnerability does
01Description
The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the id parameter in the google-map block in all versions up to, and including, 2.6.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor access and higher to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Explanation of Vulnerability in Simple Terms
02Summary
Otter Blocks contains an input validation flaw that allows authenticated users with low privileges to modify data across the site due to improper scope handling. An attacker can read and alter sensitive information affecting other users or site content. The vulnerability requires a valid WordPress account but no additional user interaction. Update to a version newer than 2.6.4.
What an attacker can do
03Attacker Capabilities
Read and modify sensitive data across the site, including other users' information and site content.
Potential impact on your site
04Site Impact
Unauthorized data disclosure and modification by low-privilege users; site content and user data integrity at risk.
Conditions required to exploit
05Prerequisites
Attacker must have a valid WordPress user account with low-level privileges (e.g., subscriber or contributor role).
Key dates
06Disclosure timeline
April 9, 2024
CVE published
April 8, 2026
Record updated