CVE-2026-0894
- EPSS 0.19%
- Veröffentlicht 18.04.2026 09:26:52
- Zuletzt bearbeitet 22.04.2026 20:22:50
The Content Blocks (Custom Post Widget) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's content_block shortcode in all versions up to, and including, 3.3.9 due to insufficient input sanitization and output escaping ...
CVE-2024-6432
- EPSS 0.28%
- Veröffentlicht 20.02.2025 10:15:11
- Zuletzt bearbeitet 25.02.2025 18:22:51
The Content Blocks (Custom Post Widget) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘content’ parameter within the plugin's shortcode Content Block in all versions up to, and including, 3.3.5 due to insufficient input sa...
CVE-2024-44051
- EPSS 0.26%
- Veröffentlicht 17.09.2024 23:15:20
- Zuletzt bearbeitet 23.04.2026 15:19:04
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Johan van der Wijk Content Blocks (Custom Post Widget) custom-post-widget allows Stored XSS.This issue affects Content Blocks (Custom Post Widget): ...
CVE-2024-3565
- EPSS 0.31%
- Veröffentlicht 01.06.2024 04:15:09
- Zuletzt bearbeitet 08.04.2026 17:18:43
The Content Blocks (Custom Post Widget) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'content_block' shortcode in all versions up to, and including, 3.3.0 due to insufficient input sanitization and output escapin...
CVE-2024-3564
- EPSS 0.62%
- Veröffentlicht 01.06.2024 04:15:08
- Zuletzt bearbeitet 08.04.2026 19:21:22
The Content Blocks (Custom Post Widget) plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.3.0 via the plugin's 'content_block' shortcode. This makes it possible for authenticated attackers, with contri...
CVE-2024-34566
- EPSS 0.25%
- Veröffentlicht 08.05.2024 11:15:24
- Zuletzt bearbeitet 28.04.2026 19:25:27
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Johan van der Wijk Content Blocks (Custom Post Widget) allows Stored XSS.This issue affects Content Blocks (Custom Post Widget): from n/a through 3....