WordPress Extra Block Design, Style, CSS for ANY Gutenberg Blocks Plugin <= 0.2.6 is vulnerable to Cross Site Request Forgery (CSRF)
No known patch is available for this vulnerability.
The affected plugin has been removed from the WordPress.org directory (reason: Security Issue), and no patched version is being distributed through the official directory. If you have the affected software installed, you should uninstall or replace it rather than wait for an update.
Description
Cross-Site Request Forgery (CSRF) in Extra Block Design plugin (≤0.2.6) allows attackers to perform unauthorized actions via crafted requests.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Cross-Site Request Forgery (CSRF) in Extra Block Design plugin (≤0.2.6) allows attackers to perform unauthorized actions via crafted requests.
Vulnerability
Cross-Site Request Forgery (CSRF) vulnerability exists in the Extra Block Design, Style, CSS for ANY Gutenberg Blocks plugin (stylist) for WordPress. Affected versions are 0.2.6 and earlier [1]. The plugin has been closed and removed from the WordPress.org directory as of December 12, 2022, with the closure reason listed as 'Security Issue' [1].
Exploitation
An attacker can craft a malicious link or webpage that, when visited by an authenticated WordPress administrator, triggers a forged request to perform unintended actions within the plugin's settings or functions. No direct authentication or network position beyond standard web access is required for the attacker; the attack relies on social engineering to trick the victim into clicking the crafted link or visiting the malicious site while logged into WordPress.
Impact
Successful exploitation allows the attacker to perform state-changing operations on the target WordPress site, such as altering plugin settings or injecting malicious CSS/scripts, potentially leading to privilege escalation or site compromise. The scope is limited to actions the victim administrator can perform, as the CSRF leverages the victim's session.
Mitigation
No patched version has been released; the plugin is closed and no longer available from the official WordPress.org directory. Users are advised to uninstall the plugin immediately. No workaround is provided by the vendor. The plugin is not listed on CISA's Known Exploited Vulnerabilities catalog as of the publication date.
AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: <=0.2.6
- StylistWP/Extra Block Design, Style, CSS for ANY Gutenberg Blocksv5Range: n/a
Patches
0stylistThis plugin has been removed from the WordPress.org directory on 2022-12-12 (reason: Security Issue). No patched version is being distributed through the official directory. Users who have it installed should uninstall it.
Source: api.wordpress.org · directory page
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.