VYPR

Lazy Blocks

by WordPress

Source repositories

CVEs (2)

  • CVE-2026-1560HigFeb 11, 2026
    risk 0.51cvss 8.8epss 0.09

    The Custom Block Builder – Lazy Blocks plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.2.0 via multiple functions in the 'LazyBlocks_Blocks' class. This makes it possible for authenticated attackers, with Contributor-level…

  • CVE-2025-58258MedSep 22, 2025
    risk 0.21cvss 4.3epss 0.00

    Missing Authorization vulnerability in nK Lazy Blocks lazy-blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Lazy Blocks: from n/a through <= 4.1.0.