VYPR

Custom Block Builder

by WordPress

CVEs (3)

  • CVE-2026-1560HigFeb 11, 2026
    risk 0.50cvss 8.8epss 0.00

    The Custom Block Builder – Lazy Blocks plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.2.0 via multiple functions in the 'LazyBlocks_Blocks' class. This makes it possible for authenticated attackers, with Contributor-level…

  • CVE-2026-8981Jun 9, 2026
    risk 0.00cvss epss

    The Custom Block Builder WordPress plugin before 4.3.0 does not consistently check the unfiltered_html capability across all paths that write to its block template code fields, allowing administrators on multisite installations (or single-site installs with…

  • CVE-2024-12878Feb 26, 2025
    risk 0.00cvss epss 0.02

    The Custom Block Builder WordPress plugin before 3.8.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.