Skip to main content

Vendor/product archive

motopress / getwid CVEs

Beta · best-effort

10 CVEs tagged to motopress / getwid0 Critical, 2 High, 8 Medium, 0 Low, 0 Unrated.

CVE-2024-10872

Published Nov 20, 2024

The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `template-post-custom-field` block in all versions up to, and including, 2.…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-6491

Published Jul 20, 2024

The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the mailchimp_api_key_manage function in…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-6489

Published Jul 20, 2024

The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the get_google_api_key function in all v…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-3588

Published May 2, 2024

The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Countdown block in all versions up to, and including, 2.0.7 due to…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-1948

Published Apr 9, 2024

The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the block content in all versions up to, and including, 2.0.5 due to insufficie…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-6963

Published Feb 5, 2024

The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to CAPTCHA Bypass in versions up to, and including, 2.0.4. This makes it possible for unauthenticated attackers to…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-6959

Published Feb 5, 2024

The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the recaptcha_api_key_manage function in…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-6042

Published Jan 8, 2024

Any unauthenticated user may send e-mail from the site with any title or content to the admin

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-1910

Published Jun 9, 2023

The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized modification of data due to an insufficient capability check on the get_remote_templates function…

CVSS 4.3 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2023-1895

Published Jun 9, 2023

The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to Server Side Request Forgery via the get_remote_content REST API endpoint in versions up to, and including, 1.8.…

CVSS 8.5 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort
Showing 1-10 of 10 CVEsPage 1 of 1