Wordpress Alert: Stored cross-site scripting in block attributes

A custom block saves a value that later executes in the editor or public page. Editors or visitors can be affected each time the block renders.

What it looks like

A custom block saves a value that later executes in the editor or public page.

Why it matters

Editors or visitors can be affected each time the block renders.

What to check

Inspect custom block rendering and sanitize allowed HTML before output.

Documentation

This is an exploit pattern to check in installed components, not a claim that every WordPress site has this flaw. Confirm the product and version against its advisories before treating a site as affected. See WordPress output escaping, WordPress input sanitizing.