CVE-2026-3498 - BlockArt Blocks <= 2.2.15 - Authenticated (Author+) Stored Cross-Site Scripting via 'clientId' Block Attribute
CVE ID :CVE-2026-3498
Published : April 11, 2026, 1:24 a.m. | 44 minutes ago
Description :The BlockArt Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'clien...
Related Vulnerabilities
- CVE-2026-34621: Acrobat Reader versions 24.001.30356, 26.001.21367 and earlier are affected by an Improperly Control CRITICAL
- CVE-2026-40100: FastGPT is an AI Agent building platform. Prior to 4.14.10.3, the /api/core/app/mcpTools/runTool end MEDIUM
- CVE-2026-6068: NASM contains a heap use after free vulnerability in response file (-@) processing where a dangling MEDIUM
- CVE-2026-4482: The installer certificate files in the …/bootstrap/common/ssl folder do not seem to have restricted MEDIUM
- CVE-2026-40158: PraisonAI is a multi-agent teams system. Prior to 4.5.128, PraisonAI's AST-based Python sandbox can HIGH
Related Coverage
Threat Actors