VYPR

Essential Blocks

by WordPress

Source repositories

CVEs (26)

  • CVE-2023-2086MedJun 9, 2023
    risk 0.28cvss 4.3epss 0.01

    The Essential Blocks plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check on the template_count function in versions up to, and including, 4.0.6. This makes it possible for subscriber-level attackers to obtain plugin template…

  • CVE-2023-2085MedJun 9, 2023
    risk 0.28cvss 4.3epss 0.01

    The Essential Blocks plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check on the templates function in versions up to, and including, 4.0.6. This makes it possible for subscriber-level attackers to obtain plugin template…

  • CVE-2023-2084MedJun 9, 2023
    risk 0.28cvss 4.3epss 0.01

    The Essential Blocks plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check on the get function in versions up to, and including, 4.0.6. This makes it possible for subscriber-level attackers to obtain plugin settings. While a…

  • CVE-2023-2083MedJun 9, 2023
    risk 0.28cvss 4.3epss 0.01

    The Essential Blocks plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check on the save function in versions up to, and including, 4.0.6. This makes it possible for subscriber-level attackers to save plugin settings. While a…

  • CVE-2024-12045MedJan 8, 2025
    risk 0.22cvss 4.4epss 0.00

    The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the maker title value of the Google Maps block in all versions up to, and including, 5.0.9 due to insufficient input sanitization…

  • CVE-2026-10833MedJun 25, 2026
    risk 0.00cvss 6.4epss 0.00

    The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'configurablePrefix' Block Attribute in all versions up to, and including, 6.1.4 due to insufficient input sanitization and…

Page 2 of 2