Low severity3.5NVD Advisory· Published Jun 9, 2026· Updated Jun 9, 2026
CVE-2026-8981
CVE-2026-8981
Description
The Custom Block Builder WordPress plugin before 4.3.0 does not consistently check the unfiltered_html capability across all paths that write to its block template code fields, allowing administrators on multisite installations (or single-site installs with DISALLOW_UNFILTERED_HTML defined) to inject arbitrary JavaScript that executes for any visitor of pages embedding the affected block.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2<4.3.0+ 1 more
- (no CPE)range: <4.3.0
- (no CPE)range: <4.3.0
Patches
Vulnerability mechanics
References
1News mentions
1- Wordfence Intelligence Weekly WordPress Vulnerability Report (June 8, 2026 to June 14, 2026)Wordfence Blog · Jun 18, 2026