CVE-2026-0894
- EPSS 0.03%
- Veröffentlicht 18.04.2026 09:26:52
- Zuletzt bearbeitet 18.04.2026 10:16:12
The Content Blocks (Custom Post Widget) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's content_block shortcode in all versions up to, and including, 3.3.9 due to insufficient input sanitization and output escaping ...
CVE-2024-6432
- EPSS 0.13%
- Veröffentlicht 20.02.2025 10:15:11
- Zuletzt bearbeitet 25.02.2025 18:22:51
The Content Blocks (Custom Post Widget) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘content’ parameter within the plugin's shortcode Content Block in all versions up to, and including, 3.3.5 due to insufficient input sa...
CVE-2024-44051
- EPSS 0.3%
- Veröffentlicht 17.09.2024 23:15:20
- Zuletzt bearbeitet 01.04.2026 16:17:58
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Johan van der Wijk Content Blocks (Custom Post Widget) custom-post-widget allows Stored XSS.This issue affects Content Blocks (Custom Post Widget): ...
CVE-2024-3565
- EPSS 0.36%
- Veröffentlicht 01.06.2024 04:15:09
- Zuletzt bearbeitet 08.04.2026 17:18:43
The Content Blocks (Custom Post Widget) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'content_block' shortcode in all versions up to, and including, 3.3.0 due to insufficient input sanitization and output escapin...
CVE-2024-3564
- EPSS 0.71%
- Veröffentlicht 01.06.2024 04:15:08
- Zuletzt bearbeitet 08.04.2026 19:21:22
The Content Blocks (Custom Post Widget) plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.3.0 via the plugin's 'content_block' shortcode. This makes it possible for authenticated attackers, with contri...
CVE-2024-34566
- EPSS 0.29%
- Veröffentlicht 08.05.2024 11:15:24
- Zuletzt bearbeitet 12.02.2025 01:40:13
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Johan van der Wijk Content Blocks (Custom Post Widget) allows Stored XSS.This issue affects Content Blocks (Custom Post Widget): from n/a through 3....