CVE-2026-4801Disclosure

LOWCVSS 6.4 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The Page Builder Gutenberg Blocks – CoBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via external iCal feed data in all versions up to, and including, 3.1.16 due to insufficient output escaping of event titles, descriptions, and locations fetched from external iCal feeds in the Events block rendering function. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-04-18); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-18: 2Mentions · 2026-04-21: 1Patch / Workaround · 2026-04-21: 1Technical Details · 2026-04-18: 204-1804-21
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-04-182
Disclosure1General1
2026-04-211
Disclosure1
Full discourse3 posts
  • CyberWolfGuard@CyberWolfGuard
    Disclosure

    WORDPRESS PLUGIN ALERT: Technical details and CVEs have been disclosed for several popular plugins. If you are running any of the following, your site is vulnerable: CVE-2026-4801 CVE-2026-2262 CVE-2026-2986 Update all plugins #WordPress #InfoSec #BugBounty #CyberAlert https://t.co/pTlTlOCdrs

    Post summary

    New CVEs (CVE‑2026‑4801, CVE‑2026‑2262, CVE‑2026‑2986) have been disclosed for popular WordPress plugins; admins are urged to update plugins to mitigate potential vulnerabilities.

    0000066
    10 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4801 The Page Builder Gutenberg Blocks – CoBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via external iCal feed data in all versions up to, and in… https://www.cve.org/CVERecord?id=CVE-2026-4801

    Post summary

    This post announces CVE‑2026‑4801, a stored XSS flaw in the CoBlocks WordPress plugin caused by external iCal feed data. No exploitation evidence or mitigation is provided.

    0000055
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-4801 Stored Cross-Site Scripting in CoBlocks WordPress Plugin via iCal Feed Data https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-4801

    Post summary

    The post links to a vulnerability details page for CVE-2026‑4801, identifying it as a stored XSS flaw in the CoBlocks WordPress plugin.

    0000043
    4.0K followersView on X

Explore more