CVE WATCH / VULNERABILITY DETAIL
CVE-2026-96256
MEDIUMCVSS 6.4NVD feed
Published 1 October 2026 · tracked since 2 October 2026
Description
The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Google Map block's 'marker' attribute in versions up to, and including, 6.4.5 This is due to insufficient input sanitization and output escaping on
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog