
CVE-2026-3498 The BlockArt Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'clientId' block attribute in all versions up to, and including, 2.2.15. T… https://www.cve.org/CVERecord?id=CVE-2026-3498
Post summary
CVE‑2026‑3498 is a stored XSS flaw in the BlockArt Blocks WordPress plugin that affects all versions up to 2.2.15 via the 'clientId' block attribute.

