
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-1093 is a Stored Cross-Site Scripting (XSS) vulnerability in the WPFAQBlock – FAQ & Accordion Plugin For Gutenberg for WordPress. It affects all versions up to and including 1.1, caused by insufficient input sanitization and output escaping on the class parameter of the wpfaqblock shortcode. Authenticated attackers with Contributor-level access or above can inject arbitrary web scripts into pages that execute when any user visits the affected page. It carries a CVSS v3.1 base score of 6.4 (Medium) (Wordfence, ENISA EUVD).
The root cause is CWE-79 (Improper Neutralization of Input During Web Page Generation – Cross-Site Scripting), specifically in the plugin's template file (includes/templates/template-1.php, line 10), where the class attribute passed via the wpfaqblock shortcode is rendered without proper sanitization or escaping (Wordfence, WordPress Plugin Trac). An attacker with at least Contributor-level WordPress access can craft a shortcode with a malicious class value containing JavaScript, which is then stored in the database and rendered to all subsequent page visitors. No special configuration or elevated privileges beyond Contributor access are required, and exploitation occurs over the network with low attack complexity.
Successful exploitation allows an attacker to execute arbitrary JavaScript in the browsers of users who visit pages containing the injected shortcode, impacting both confidentiality (e.g., session cookie theft, credential harvesting) and integrity (e.g., page content manipulation, phishing redirects). Because the payload is stored server-side, all visitors to the affected page are at risk, not just those who interact with a specific link. Availability is not directly impacted, but the scope is changed as the injected script executes in the context of the victim's browser session (Wordfence).
No public exploit code or active in-the-wild exploitation has been reported for CVE-2026-1093 as of the latest available data. The EPSS score is approximately 0.03%, indicating a low probability of near-term exploitation (Feedly). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The requirement for at least Contributor-level authentication limits the attack surface compared to unauthenticated XSS vulnerabilities.
/wp-content/plugins/wpfaqblock/readme.txt.wpfaqblock shortcode with a malicious class parameter, e.g., [wpfaqblock class="\" onmouseover=\"alert(document.cookie)\""] or a more sophisticated payload that exfiltrates session cookies to an attacker-controlled server.class attribute and executes the injected JavaScript.wpfaqblock shortcodes with unusual class attribute values containing HTML event handlers (e.g., onmouseover, onerror) or JavaScript URIs.wp_posts table containing wpfaqblock shortcodes with class parameters that include script tags or JavaScript event attributes.wpfaqblock shortcode, potentially indicating cookie or credential exfiltration.includes/templates/template-1.php in the plugin directory for any unauthorized modifications (Wordfence).As of the disclosure date (March 21, 2026), no patched version of the WPFAQBlock plugin has been confirmed available; all versions up to and including 1.1 are affected (Wordfence). Site administrators should consider deactivating and removing the plugin until a patched version is released. As a compensating control, restrict Contributor-level user registrations and audit existing Contributor accounts. Deploying a Web Application Firewall (WAF) with XSS filtering rules can help block exploitation attempts in the interim.
The vulnerability was assigned and disclosed by Wordfence, which maintains a threat intelligence feed for WordPress plugin vulnerabilities. No notable independent researcher commentary, vendor statements beyond the Wordfence advisory, or significant social media discussion has been identified for this CVE (Wordfence).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."