MEDIUM
Ronald Huereca
CVE published 2026-04-08
CVE-2026-39575
CVE-2026-39575 is a DOM-Based XSS vulnerability in the Custom Query Blocks plugin for WordPress, affecting versions from n/a through <= 5.5.0. The vulnerability is classified as Improper Neutralization of Input During Web Page Generation, also known as Cross-site Scripting (XSS). This issue allows an attacker to execute malicious scripts in the context of a user's browser, potentially leading to unauthori [truncated]