CVE-2026-3498 - BlockArt Blocks <= 2.2.15 - Authenticated (Author+) Stored Cross-Site Scripting via 'clientId' Block Attribute
CVE ID :CVE-2026-3498
Published : April 11, 2026, 1:24 a.m. | 44 minutes ago
Description :The BlockArt Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'clien...
Related Vulnerabilities
- CVE-2026-34621: Acrobat Reader versions 24.001.30356, 26.001.21367 and earlier are affected by an Improperly Control CRITICAL
- CVE-2026-33698: Chamilo LMS is a learning management system. Prior to 1.11.38, a chained attack can enable otherwise N/A
- CVE-2026-5777: This vulnerability exists in the Atom 3x Projector due to improper exposure of the Android Debug Bri HIGH
- CVE-2026-32932: Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, an Open Redirect vulne MEDIUM
- CVE-2026-5412: In Juju versions prior to 2.9.57 and 3.6.21, an authorization issue exists in the Controller facade. CRITICAL
Related Coverage
Threat Actors