Wpengine

Genesis Blocks

3 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.07%
  • Published 15.05.2025 20:15:53
  • Last modified 05.06.2025 14:24:24

The Genesis Blocks WordPress plugin through 3.1.3 does not properly escape attributes provided to some of its custom blocks, making it possible for users allowed to write posts (like those with the contributor role) to conduct Stored XSS attacks.

  • EPSS 0.22%
  • Published 09.07.2024 09:15:04
  • Last modified 21.11.2024 09:29:53

The Genesis Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Sharing block in all versions up to, and including, 3.1.3 due to insufficient input sanitization and output escaping on user supplied attributes. Th...

Exploit
  • EPSS 0.32%
  • Published 19.04.2024 05:15:49
  • Last modified 30.05.2025 16:00:15

The Genesis Blocks WordPress plugin before 3.1.3 does not properly escape data input provided to some of its blocks, allowing using with at least contributor privileges to conduct Stored XSS attacks.