← WordPress Vulnerabilities
WordPress security by component

Custom Block Builder – Lazy Blocks

Custom Block Builder – Lazy Blocks is a WordPress component with 3 published CVE records in this archive. The latest tracked vulnerability was published Feb 11, 2026; the highest CVE/CNA score is 8.8.

Plugin slug: lazy-blocks

CVE-2026-1560: Custom Block Builder – Lazy Blocks: Code execution

Custom Block Builder – Lazy Blocks is affected by code execution. Exploitation requires at least contributor-level access. Successful exploitation can run attacker-controlled code in the WordPress hosting account.

PublishedFeb 11, 2026
Safe version guidanceSee mitigation notes
Safe version
Feb 11, 2026 CVE-2026-1560
Custom Block Builder – Lazy Blocks: Code execution
Custom Block Builder – Lazy Blocks is affected by code execution. Exploitation requires at least contributor-level access. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE8.8
NVDPending
Sep 22, 2025 CVE-2025-58258
Lazy Blocks: A security weakness
Lazy Blocks is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
Feb 26, 2025 CVE-2024-12878
Custom Block Builder: Cross-site scripting
Custom Block Builder is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVDPending