CVE-2026-3498 - BlockArt Blocks <= 2.2.15 - Authenticated (Author+) Stored Cross-Site Scripting via 'clientId' Block Attribute
CVE ID :CVE-2026-3498
Published : April 11, 2026, 1:24 a.m. | 44 minutes ago
Description :The BlockArt Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'clien...
Related Vulnerabilities
- CVE-2026-39922: GeoNode versions 4.0 before 4.4.5 and 5.0 before 5.0.2 contain a server-side request forgery vulnera N/A
- CVE-2026-6034: A flaw has been found in code-projects Vehicle Showroom Management System 1.0. Impacted is an unknow MEDIUM
- CVE-2026-35669: OpenClaw before 2026.3.25 contains a privilege escalation vulnerability in gateway-authenticated plu HIGH
- CVE-2026-40151: PraisonAI is a multi-agent teams system. Prior to 4.5.128, the AgentOS deployment platform exposes a MEDIUM
- CVE-2026-32894: Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, an Insecure Direct Obj HIGH
Related Coverage
Threat Actors