CVE-2026-75019

Cozy Blocks <= 2.2.16 - Authenticated (Contributor+) Stored Cross-Site Scripting via cozyHoverEffect Block Attribute

The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 700+ Patterns, 58 Blocks & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via cozyHoverEffect Block Attribute in all versions up to, and including, 2.2.16 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The payload survives wp_kses_post on save because it contains no angle brackets — only a double-quote breakout of the cozyHoverEffect.boxShadow.color attribute value — allowing event-handler injection at the render stage.


We have discovered 594 live websites that are affected by CVE-2026-75019.

Run a Free Instant Scan




Affected Software

Product  Cozy Addons
Category Wordpress Plugins
Vulnerable Domains594 live websites (100% of Cozy Addons install base)
Vulnerable Versions
  • from 0 through 2.2.16
Vulnerable Versions Count35 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Aug 25, 2026
  • Updated - Aug 25, 2026

Credits

  • Wordfence PRISM (finder)

Website Distribution by Country

Number of websites using CVE-2026-75019
United States258 websites



Germany38 websites
GB31 websites
India24 websites
France23 websites
Cyprus22 websites
Turkey14 websites
Brazil10 websites
Canada10 websites
Poland9 websites

Website Distribution by TLD

Number of websites using CVE-2026-75019
.com311 websites
.org41 websites
.net30 websites
.de16 websites
.co.uk13 websites
.fr11 websites
.ca9 websites
.com.br9 websites
.pl8 websites
.nl6 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-75019

Top websites that are affected by CVE-2026-75019. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****.net United States**,***
*******************.org United States***,***
******.com United States***,***
**************.com United States***,***
*****.net United States***,***
***********.org United States***,***
******.com United States***,***
**********.com France***,***
***********.com United States***,***
*********.com United States***,***
See full domain list

FAQ

CVE-2026-75019 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Cozy Addons
A total of 594 websites have been identified as vulnerable to CVE-2026-75019, based on global website indexing conducted by WebTechSurvey.
The Cozy Addons is affected by the CVE-2026-75019 vulnerability.
Cozy Addons versions up to and including 2.2.16 are vulnerable to CVE-2026-75019.