VYPR

Static Block

by WordPress

CVEs (1)

  • CVE-2026-10780MedJun 16, 2026
    risk 0.28cvss 4.3epss 0.00

    The Static Block plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.2. This is due to the static_block_content() shortcode handler retrieving a post via get_post() using an attacker-supplied 'id' attribute and…