← العودة للجدول
CVE-2026-18488
CVE-2026-18488 | creativethemeshq Blocksy Companion Plugin up to 2.1.51 on WordPress Block Attribute tagName cross site scripting
📅 2026-09-01
🟡 Medium 🔥 No VulDB Vulnerability WordPress

📋 الوصف الكامل

A vulnerability was found in creativethemeshq Blocksy Companion Plugin up to 2.1.51 on WordPress and classified as problematic. This affects an unknown function of the component Block Attribute. The manipulation of the argument tagName results in cross site scripting. This vulnerability was named CVE-2026-18488. The attack may be performed from remote. There is no available exploit.

💻 الأنظمة المتأثرة

WordPress

⚠️ نوع التهديد

Vulnerability

🔗 CVE ID

CVE-2026-18488

📡 المصدر

VulDB

✅ الحلول والتخفيف

Apply vendor security patch

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ← 🔍 Valters IT ←