Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-4801

23
FAUCET Score

OVERVIEW CVE-2026-4801 is a Stored Cross-Site Scripting (XSS) vulnerability in the CoBlocks (Page Builder Gutenberg Blocks) WordPress plugin affecting all versions through 3.1.16. The flaw exists in the Events block functionality, where insufficient output escaping of event data from external iCal feeds allows injection of malicious scripts into page content. SEVERITY The vulnerability carries a CVSS 3.1 score of 6.4 (Medium) and requires network access with low complexity. However, exploitation is restricted to authenticated users with Contributor-level access or higher, limiting the attacker pool to internal or previously compromised accounts. The injected scripts execute in the context of other users accessing the infected pages, potentially compromising site visitors through credential theft or malware distribution. EXPLOITATION STATUS There is currently no evidence of active exploitation, with the vulnerability absent from the Known Exploited Vulnerabilities (KEV) catalog and carrying a minimal EPSS score of 0.00016. No public exploit code is available, and the vulnerability remains inactive on threat intelligence hot lists. However, the moderate CVSS score and low technical barrier to exploitation warrant timely patching to prevent opportunistic attacks as awareness increases.

Impacted Technologies

VendorProductVersion(s)CPE
GodaddyPage Builder Gutenberg Blocks – CoBlocks
>= 0, <= 3.1.16CNA affecteddefault unaffected

CVSS Data

CVSS version used by this source: 3.1

6.4MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
3.1
Impact Score
2.7
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.41%
Probability of exploitation in next 30 days
EPSS Percentile
33.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0041 is in the 43rd percentile among its peer group of 21,977 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

plugins.trac.wordpress.org / browser/coblocks/tags/3.1.16/src/blocks/events/index.php
plugins.trac.wordpress.org / browser/coblocks/tags/3.1.16/src/blocks/events/index.php
plugins.trac.wordpress.org / browser/coblocks/tags/3.1.16/src/blocks/events/index.php
plugins.trac.wordpress.org / browser/coblocks/tags/3.1.16/src/blocks/events/index.php
plugins.trac.wordpress.org / browser/coblocks/tags/3.1.16/src/blocks/events/index.php
plugins.trac.wordpress.org / browser/coblocks/trunk/src/blocks/events/index.php
plugins.trac.wordpress.org / browser/coblocks/trunk/src/blocks/events/index.php
plugins.trac.wordpress.org / browser/coblocks/trunk/src/blocks/events/index.php
plugins.trac.wordpress.org / browser/coblocks/trunk/src/blocks/events/index.php
plugins.trac.wordpress.org / browser/coblocks/trunk/src/blocks/events/index.php
plugins.trac.wordpress.org / changeset/3475789/coblocks/trunk/src/blocks/events/index.php
plugins.trac.wordpress.org / changeset
wordfence.com / threat-intel/vulnerabilities/id/bde0aef3-aa61-4ee7-9cbf-9f51cb5ac700