VYPR

Custom Block Builder

by WordPress

CVEs (3)

  • CVE-2026-1560HigFeb 11, 2026
    risk 0.50cvss 8.8epss 0.09

    The Custom Block Builder – Lazy Blocks plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.2.0 via multiple functions in the 'LazyBlocks_Blocks' class. This makes it possible for authenticated attackers, with Contributor-level…

  • CVE-2024-12878HigFeb 26, 2025
    risk 0.46cvss 7.1epss 0.01

    The Custom Block Builder WordPress plugin before 3.8.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

  • CVE-2026-8981LowJun 9, 2026
    risk 0.23cvss 3.5epss 0.00

    The Custom Block Builder WordPress plugin before 4.3.0 does not consistently check the unfiltered_html capability across all paths that write to its block template code fields, allowing administrators on multisite installations (or single-site installs with…