VYPR

Spectra Gutenberg Blocks

by WordPress

CVEs (4)

  • CVE-2026-7465HigMay 30, 2026
    risk 0.57cvss 8.8epss 0.01

    The Spectra Gutenberg Blocks – Website Builder for the Block Editor plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.19.25. This makes it possible for authenticated attackers, with Contributor-level access and above, to…

  • CVE-2026-0950MedFeb 3, 2026
    risk 0.34cvss 5.3epss 0.00

    The Spectra Gutenberg Blocks – Website Builder for the Block Editor plugin for WordPress is vulnerable to Information Disclosure in all versions up to, and including, 2.19.17. This is due to the plugin failing to check `post_password_required()` before rendering post excerpts…

  • CVE-2026-16302MedSep 24, 2026
    risk 0.21cvss 4.3epss 0.00

    The Spectra Legacy – Gutenberg Blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.20.0 via the editor_assets function, which exposes the uag_insta_linked_accounts option through the uagb_blocks_info object…

  • CVE-2026-12900MedJul 20, 2026
    risk 0.00cvss 6.4epss 0.00

    The Spectra Gutenberg Blocks – Website Builder for the Block Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `uagb/image` block in all versions up to, and including, 2.19.28 due to insufficient input sanitization and output escaping. This makes…