Unknown Page Builder Gutenberg Blocks vulnerabilities
3 known vulnerabilities affecting unknown/page_builder_gutenberg_blocks.
Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM3
Vulnerabilities
Page 1 of 1
CVE-2024-7132MEDIUMCVSS 4.8fixed in 3.1.132024-08-29
CVE-2024-7132 [MEDIUM] CWE-79 CVE-2024-7132: The Page Builder Gutenberg Blocks WordPress plugin before 3.1.13 does not escape the content of pos
The Page Builder Gutenberg Blocks WordPress plugin before 3.1.13 does not escape the content of post embed via one of its block, which could allow users with the capability to publish posts (editor and admin by default) to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
cvelistv5nvd
CVE-2024-4260MEDIUMCVSS 6.5fixed in 3.1.122024-07-23
CVE-2024-4260 [MEDIUM] CWE-918 CVE-2024-4260: The Page Builder Gutenberg Blocks WordPress plugin before 3.1.12 does not prevent users from pingin
The Page Builder Gutenberg Blocks WordPress plugin before 3.1.12 does not prevent users from pinging arbitrary hosts via some of its shortcodes, which could allow high privilege users such as contributors to perform SSRF attacks.
cvelistv5nvd
CVE-2024-2369MEDIUMCVSS 5.4fixed in 3.1.72024-04-02
CVE-2024-2369 [MEDIUM] CWE-79 CVE-2024-2369: The Page Builder Gutenberg Blocks WordPress plugin before 3.1.7 does not validate and escape some of
The Page Builder Gutenberg Blocks WordPress plugin before 3.1.7 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
cvelistv5nvd