CVE-2025-2918
- EPSS 0.18%
- Veröffentlicht 10.06.2025 11:22:52
- Zuletzt bearbeitet 14.07.2025 17:25:14
The Ultimate Blocks – WordPress Blocks Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 3.3.3 due to insufficient input sanitization and output escaping. This makes it...
CVE-2024-10678
- EPSS 0.16%
- Veröffentlicht 13.12.2024 06:15:24
- Zuletzt bearbeitet 08.05.2025 19:43:07
The Ultimate Blocks WordPress plugin before 3.2.4 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stor...
CVE-2024-8536
- EPSS 0.41%
- Veröffentlicht 30.09.2024 06:15:14
- Zuletzt bearbeitet 03.10.2024 18:16:17
The Ultimate Blocks WordPress plugin before 3.2.2 does not validate and escape some of its block attributes before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform S...
CVE-2024-6362
- EPSS 0.16%
- Veröffentlicht 29.07.2024 06:15:02
- Zuletzt bearbeitet 29.05.2025 17:34:19
The Ultimate Blocks WordPress plugin before 3.2.0 does not validate and escape some of its post-grid block attributes before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to...
CVE-2024-37457
- EPSS 0.11%
- Veröffentlicht 21.07.2024 23:15:02
- Zuletzt bearbeitet 21.11.2024 09:23:52
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Ultimate Blocks Ultimate Blocks – Gutenberg Blocks Plugin allows Stored XSS.This issue affects Ultimate Blocks – Gutenberg Blocks Plugin: fro...
CVE-2024-4655
- EPSS 0.2%
- Veröffentlicht 11.07.2024 06:15:02
- Zuletzt bearbeitet 21.11.2024 09:43:18
The Ultimate Blocks WordPress plugin before 3.1.9 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stor...
CVE-2024-4268
- EPSS 0.36%
- Veröffentlicht 02.07.2024 11:15:10
- Zuletzt bearbeitet 08.04.2026 17:18:51
The Ultimate Blocks – WordPress Blocks Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's blocks in all versions up to, and including, 3.1.9 due to insufficient input sanitization and output escaping on user sup...
CVE-2024-3513
- EPSS 0.23%
- Veröffentlicht 02.07.2024 08:15:06
- Zuletzt bearbeitet 08.04.2026 18:21:26
The Ultimate Blocks – WordPress Blocks Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the title tag (postTitleTag) parameter in all versions up to, and including, 3.1.9 due to insufficient input sanitization and output e...
CVE-2024-3241
- EPSS 0.25%
- Veröffentlicht 14.05.2024 16:17:31
- Zuletzt bearbeitet 14.05.2025 16:47:45
The Ultimate Blocks WordPress plugin before 3.1.7 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stor...