CPE
The Extendify plugin for WordPress is vulnerable to unauthenticated Stored Cross-Site Scripting (XSS) via the 'styles.blocks' parameter, allowing arbitrary script injection.