WP Blockade Reflected Cross-Site Scripting Vulnerability

Vulnerability

A reflected cross-site scripting vulnerability has been identified in the WP Blockade plugin for WordPress, affecting all versions through 0.9.14. The issue arises from inadequate input sanitization and output escaping in the render_shortcode_preview() function. This function processes user input from the 'shortcode' parameter without proper sanitization, allowing malicious scripts to be injected and executed on the page. The vulnerability requires the user to be logged in with at least a Subscriber-level account.

Impact

Exploitation of this vulnerability allows authenticated users with Subscriber-level access to inject and execute arbitrary JavaScript in the context of the user viewing the page.

Added: May 22, 2026, 5:23 AM
Updated: May 22, 2026, 5:23 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.7
exploitability
5.5
remediation
0.0
relevance
8.9
threat
3.2
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.