OVERVIEW CVE-2026-4801 is a Stored Cross-Site Scripting (XSS) vulnerability in the CoBlocks (Page Builder Gutenberg Blocks) WordPress plugin affecting all versions through 3.1.16. The flaw exists in the Events block functionality, where insufficient output escaping of event data from external iCal feeds allows injection of malicious scripts into page content. SEVERITY The vulnerability carries a CVSS 3.1 score of 6.4 (Medium) and requires network access with low complexity. However, exploitation is restricted to authenticated users with Contributor-level access or higher, limiting the attacker pool to internal or previously compromised accounts. The injected scripts execute in the context of other users accessing the infected pages, potentially compromising site visitors through credential theft or malware distribution. EXPLOITATION STATUS There is currently no evidence of active exploitation, with the vulnerability absent from the Known Exploited Vulnerabilities (KEV) catalog and carrying a minimal EPSS score of 0.00016. No public exploit code is available, and the vulnerability remains inactive on threat intelligence hot lists. However, the moderate CVSS score and low technical barrier to exploitation warrant timely patching to prevent opportunistic attacks as awareness increases.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Godaddy | Page Builder Gutenberg Blocks – CoBlocks | >= 0, <= 3.1.16CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.