VYPR

Maxi Blocks

by WordPress

Source repositories

CVEs (4)

  • CVE-2025-47601HigJun 7, 2025
    risk 0.57cvss 8.8epss 0.00

    Missing Authorization vulnerability in Christiaan Pieterse MaxiBlocks maxi-blocks allows Privilege Escalation.This issue affects MaxiBlocks: from n/a through <= 2.1.0.

  • CVE-2024-6885HigJul 23, 2024
    risk 0.53cvss 8.1epss 0.01

    The MaxiBlocks: 2200+ Patterns, 190 Pages, 14.2K Icons & 100 Styles plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the maxi_remove_custom_image_size and maxi_add_custom_image_size functions in all versions up to, and…

  • CVE-2025-58968MedSep 22, 2025
    risk 0.33cvss 5.0epss 0.00

    Missing Authorization vulnerability in Christiaan Pieterse MaxiBlocks maxi-blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MaxiBlocks: from n/a through <= 2.1.3.

  • CVE-2026-2028MedApr 24, 2026
    risk 0.27cvss 5.3epss 0.00

    The MaxiBlocks Builder plugin for WordPress is vulnerable to arbitrary media file deletion due to insufficient file ownership validation on the 'maxi_remove_custom_image_size' AJAX action in all versions up to, and including, 2.1.8. This makes it possible for authenticated…