VYPR

Essential Blocks

by WordPress

Source repositories

CVEs (26)

  • CVE-2023-6623CriJan 15, 2024
    risk 0.68cvss 9.8epss 0.51

    The Essential Blocks WordPress plugin before 4.4.3 does not prevent unauthenticated attackers from overwriting local variables when rendering templates over the REST API, which may lead to Local File Inclusion attacks.

  • CVE-2023-4386HigOct 20, 2023
    risk 0.53cvss 8.1epss 0.01

    The Essential Blocks plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.2.0 via deserialization of untrusted input in the get_posts function. This allows unauthenticated attackers to inject a PHP Object. No POP chain is present in the…

  • CVE-2023-4402HigOct 20, 2023
    risk 0.53cvss 8.1epss 0.01

    The Essential Blocks plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.2.0 via deserialization of untrusted input in the get_products function. This allows unauthenticated attackers to inject a PHP Object. No POP chain is present in…

  • CVE-2026-13154HigAug 6, 2026
    risk 0.49cvss 7.5epss 0.00

    The Gutenberg Essential Blocks WordPress plugin before 6.4.0 does not verify that an attacker-supplied post type is publicly viewable before querying it in one of its public REST routes, allowing unauthenticated users to read published entries of custom post types that the site…

  • CVE-2026-13153HigAug 6, 2026
    risk 0.49cvss 7.5epss 0.00

    The Gutenberg Essential Blocks WordPress plugin before 6.4.0 does not restrict access to one of its public REST routes and over-fetches a non-public WooCommerce per-product sales metric into the response, allowing unauthenticated users to read the lifetime number of units sold…

  • CVE-2026-10586HigJun 5, 2026
    risk 0.47cvss 7.2epss 0.00

    The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6.1.3 via the `save_ai_generated_image()` function. This makes it possible for authenticated…

  • CVE-2026-4658MedMay 2, 2026
    risk 0.42cvss 6.4epss 0.00

    The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the className, classHook, and blockId attributes in the Add to Cart block (essential-blocks/add-to-cart) in all versions up to, and…

  • CVE-2025-11361MedOct 18, 2025
    risk 0.42cvss 6.4epss 0.00

    The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5.7.1 via the eb_save_ai_generated_image function. This makes it possible for authenticated…

  • CVE-2024-13803MedFeb 26, 2025
    risk 0.42cvss 6.4epss 0.00

    The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data-marker’ parameter in all versions up to, and including, 5.2.3 due to insufficient input sanitization and output…

  • CVE-2024-1854MedMar 13, 2024
    risk 0.42cvss 6.4epss 0.00

    The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the blockId parameter in all versions up to, and including, 4.5.1 due to insufficient input sanitization and output escaping. This…

  • CVE-2025-11270MedOct 18, 2025
    risk 0.35cvss 6.4epss 0.00

    The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'titleTag' attribute in all versions up to, and including, 5.7.1 due to insufficient input sanitization and output escaping.…

  • CVE-2025-4682MedMay 27, 2025
    risk 0.35cvss 6.4epss 0.00

    The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via HTML attributes in Slider and Post Carousel widgets in all versions up to, and including, 5.4.0 due to insufficient input…

  • CVE-2025-1664MedMar 8, 2025
    risk 0.35cvss 6.4epss 0.00

    The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Parallax slider in all versions up to, and including, 5.3.1 due to insufficient input sanitization and output escaping. This…

  • CVE-2024-5595MedAug 2, 2024
    risk 0.35cvss 5.4epss 0.00

    The Essential Blocks WordPress plugin before 4.7.0 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting…

  • CVE-2024-4891MedMay 18, 2024
    risk 0.35cvss 6.4epss 0.00

    The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘tagName’ parameter in versions up to, and including, 4.5.12 due to insufficient input sanitization and output escaping.…

  • CVE-2024-2255MedMar 20, 2024
    risk 0.35cvss 6.4epss 0.01

    The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets in all versions up to, and including, 4.5.3 due to insufficient input sanitization and output escaping on user…

  • CVE-2023-7071MedJan 11, 2024
    risk 0.35cvss 6.4epss 0.00

    The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Table of Contents block in all versions up to, and including, 4.4.6 due to insufficient input sanitization and output escaping.…

  • CVE-2025-11369MedDec 17, 2025
    risk 0.28cvss 4.3epss 0.00

    The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to unauthorized access of data due to a missing or incorrect capability checks on the get_instagram_access_token_callback, google_map_api_key_save_callback and…

  • CVE-2024-3818MedApr 19, 2024
    risk 0.28cvss 5.4epss 0.00

    The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's "Social Icons" block in all versions up to, and including, 4.5.9 due to insufficient input sanitization and output…

  • CVE-2023-2087MedJun 9, 2023
    risk 0.28cvss 4.3epss 0.00

    The Essential Blocks plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.0.6. This is due to missing or incorrect nonce validation on the save function. This makes it possible for unauthenticated attackers to change plugin…

Page 1 of 2