CVE-2026-15393

Cozy Blocks <= 2.2.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'postMeta.font.size' Block Attribute

The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'postMeta.font.size' Block Attribute in all versions up to, and including, 2.2.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.


We have discovered 598 live websites that are affected by CVE-2026-15393.

Run a Free Instant Scan




Affected Software

Product  Cozy Addons
Category Wordpress Plugins
Vulnerable Domains598 live websites (100% of Cozy Addons install base)
Vulnerable Versions
  • from 0 through 2.2.11
Vulnerable Versions Count32 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Jul 28, 2026
  • Updated - Jul 28, 2026

Credits

  • Wordfence PRISM (finder)

Website Distribution by Country

Number of websites using CVE-2026-15393
United States260 websites



Germany40 websites
GB32 websites
India24 websites
France24 websites
Cyprus21 websites
Turkey15 websites
Brazil10 websites
Canada10 websites
Italy9 websites

Website Distribution by TLD

Number of websites using CVE-2026-15393
.com317 websites
.org42 websites
.net29 websites
.de16 websites
.co.uk13 websites
.fr10 websites
.ca9 websites
.com.br9 websites
.pl8 websites
.nl6 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-15393

Top websites that are affected by CVE-2026-15393. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****.net United States**,***
*******************.org United States***,***
******.com United States***,***
**************.com United States***,***
*****.net United States***,***
***********.org United States***,***
******.com United States***,***
**********.com France***,***
***********.com United States***,***
*********.com United States***,***
See full domain list

FAQ

CVE-2026-15393 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Cozy Addons
A total of 598 websites have been identified as vulnerable to CVE-2026-15393, based on global website indexing conducted by WebTechSurvey.
The Cozy Addons is affected by the CVE-2026-15393 vulnerability.
Cozy Addons versions up to and including 2.2.11 are vulnerable to CVE-2026-15393.

References