CVE-2026-25438 identifies a Reflected Cross-site Scripting (XSS) vulnerability in the ThemeHunk Gutenberg Blocks unlimited-blocks plugin, affecting versions up to and including 1.2.8. Rated 7.1 HIGH, this flaw allows a remote attacker to inject malicious scripts into web pages due to improper input neutralization, requiring user interaction to trigger. Successful exploitation could lead to limited data theft, content defacement, or redirection, with a low impact on confidentiality, integrity, and availability. There is currently no evidence of active exploitation, nor is public exploit code available, and community discussion or media coverage is minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, <= 1.2.8CPE match | cpe:2.3:a:themehunk:gutenberg_blocks:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Remediation records are not available for this CVE.