Skip to main content

Vendor/product archive

wpdeveloper / essential_blocks CVEs

Beta · best-effort

25 CVEs tagged to wpdeveloper / essential_blocks1 Critical, 2 High, 22 Medium, 0 Low, 0 Unrated.

CVE-2025-1664

Published Mar 8, 2025

The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Parallax slider in all version…

CVSS 6.4 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2024-13803

Published Feb 26, 2025

The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data-marker’ parameter in all…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-26871

Published Feb 25, 2025

Missing Authorization vulnerability in WPDeveloper Essential Blocks for Gutenberg essential-blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This iss…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-12045

Published Jan 8, 2025

The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the maker title value of the Googl…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-47594

Published Dec 13, 2024

Missing Authorization vulnerability in WPDeveloper Essential Blocks for Gutenberg allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Essent…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-51360

Published Dec 9, 2024

Missing Authorization vulnerability in WPDeveloper Essential Blocks for Gutenberg essential-blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This iss…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-51359

Published Dec 9, 2024

Missing Authorization vulnerability in WPDeveloper Essential Blocks for Gutenberg essential-blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This iss…

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-47760

Published Dec 9, 2024

Missing Authorization vulnerability in WPDeveloper Essential Blocks for Gutenberg essential-blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This iss…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-47385

Published Oct 5, 2024

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPDeveloper Essential Blocks for Gutenberg essential-blocks allows Stored XSS…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-5595

Published Aug 2, 2024

The Essential Blocks WordPress plugin before 4.7.0 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, whi…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-30467

Published Jun 9, 2024

Missing Authorization vulnerability in WPDeveloper Essential Blocks for Gutenberg.This issue affects Essential Blocks for Gutenberg: from n/a through 4.4.9.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-4891

Published May 18, 2024

The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘tagName’ parameter in version…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-3818

Published Apr 19, 2024

The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's "Social Icons" block…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-31306

Published Apr 7, 2024

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPDeveloper Essential Blocks for Gutenberg allows Stored XSS.This issue affec…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-2255

Published Mar 20, 2024

The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets in all versio…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-1854

Published Mar 13, 2024

The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the blockId parameter in all versi…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-6623

Published Jan 15, 2024

The Essential Blocks WordPress plugin before 4.4.3 does not prevent unauthenticated attackers from overwriting local variables when rendering templates over the REST API, which ma…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-7071

Published Jan 11, 2024

The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Table of Contents block in all…

CVSS 6.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-4386

Published Oct 20, 2023

The Essential Blocks plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.2.0 via deserialization of untrusted input in the get_posts fun…

CVSS 8.1 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2023-2087

Published Jun 9, 2023

The Essential Blocks plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.0.6. This is due to missing or incorrect nonce validation…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-2086

Published Jun 9, 2023

The Essential Blocks plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check on the template_count function in versions up to, an…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-2085

Published Jun 9, 2023

The Essential Blocks plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check on the templates function in versions up to, and inc…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-2084

Published Jun 9, 2023

The Essential Blocks plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check on the get function in versions up to, and including…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-2083

Published Jun 9, 2023

The Essential Blocks plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check on the save function in versions up to, and includin…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 1-25 of 25 CVEsPage 1 of 1