CVE-2025-2918
- EPSS 0.05%
- Veröffentlicht 10.06.2025 11:22:52
- Zuletzt bearbeitet 14.07.2025 17:25:14
The Ultimate Blocks – WordPress Blocks Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 3.3.3 due to insufficient input sanitization and output escaping. This makes it...
CVE-2024-10678
- EPSS 0.16%
- Veröffentlicht 13.12.2024 06:15:24
- Zuletzt bearbeitet 08.05.2025 19:43:07
The Ultimate Blocks WordPress plugin before 3.2.4 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stor...
CVE-2024-8536
- EPSS 0.54%
- Veröffentlicht 30.09.2024 06:15:14
- Zuletzt bearbeitet 03.10.2024 18:16:17
The Ultimate Blocks WordPress plugin before 3.2.2 does not validate and escape some of its block attributes before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform S...
CVE-2024-6362
- EPSS 0.16%
- Veröffentlicht 29.07.2024 06:15:02
- Zuletzt bearbeitet 29.05.2025 17:34:19
The Ultimate Blocks WordPress plugin before 3.2.0 does not validate and escape some of its post-grid block attributes before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to...
CVE-2024-37457
- EPSS 0.11%
- Veröffentlicht 21.07.2024 23:15:02
- Zuletzt bearbeitet 21.11.2024 09:23:52
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Ultimate Blocks Ultimate Blocks – Gutenberg Blocks Plugin allows Stored XSS.This issue affects Ultimate Blocks – Gutenberg Blocks Plugin: fro...
CVE-2024-4655
- EPSS 0.11%
- Veröffentlicht 11.07.2024 06:15:02
- Zuletzt bearbeitet 21.11.2024 09:43:18
The Ultimate Blocks WordPress plugin before 3.1.9 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stor...
CVE-2024-4268
- EPSS 0.27%
- Veröffentlicht 02.07.2024 11:15:10
- Zuletzt bearbeitet 21.11.2024 09:42:30
The Ultimate Blocks – WordPress Blocks Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's blocks in all versions up to, and including, 3.1.9 due to insufficient input sanitization and output escaping on user sup...
CVE-2024-3513
- EPSS 0.22%
- Veröffentlicht 02.07.2024 08:15:06
- Zuletzt bearbeitet 21.11.2024 09:29:45
The Ultimate Blocks – WordPress Blocks Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the title tag parameter in all versions up to, and including, 3.1.9 due to insufficient input sanitization and output escaping. This m...
CVE-2024-3241
- EPSS 0.33%
- Veröffentlicht 14.05.2024 16:17:31
- Zuletzt bearbeitet 14.05.2025 16:47:45
The Ultimate Blocks WordPress plugin before 3.1.7 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stor...