| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2025-22674 | WordPress Product Blocks for WooCommerce plugin <= 1.9.1 - Cross Site Scripting (XSS) vulnerability | Get Bowtied | Product Blocks for WooCommerce | Medium | 6.5 | 2025-02-04 14:21:58 | Deep Dive |
| CVE-2025-22697 | WordPress Responsive Blocks plugin <= 1.9.9 - Cross Site Scripting (XSS) vulnerability | CyberChimps | Responsive Blocks | Medium | 6.5 | 2025-02-04 14:21:14 | Deep Dive |
| CVE-2024-13733 | SKT Blocks – Gutenberg based Page Builder <= 1.7 - Authenticated (Contributor+) Stored Cross-Site Scripting | sonalsinha21 | SKT Blocks – Gutenberg based Page Builder | Medium | 6.4 | 2025-02-04 09:21:08 | Deep Dive |
| CVE-2024-12620 | AnimateGL Animations for WordPress – Elementor & Gutenberg Blocks Animations <= 1.4.23 - Missing Authorization to Unauthenticated Settings Update | creativeinteractivemedia | AnimateGL Animations for WordPress – Elementor & Gutenberg Blocks Animations | Medium | 5.3 | 2025-02-01 03:21:12 | Deep Dive |
| CVE-2024-13549 | All Bootstrap Blocks <= 1.3.26 - Authenticated (Contributor+) Stored Cross-Site Scripting | areoimiles | All Bootstrap Blocks | Medium | 6.4 | 2025-01-30 13:42:01 | Deep Dive |
| CVE-2024-13732 | Responsive Blocks – WordPress Gutenberg Blocks <= 1.9.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via section_tag Parameter | cyberchimps | Responsive Blocks – Page Builder for Blocks & Patterns | Medium | 6.4 | 2025-01-30 08:21:25 | Deep Dive |
| CVE-2025-24753 | WordPress Kadence Blocks plugin <= 3.3.1 - Broken Access Control vulnerability | StellarWP | Gutenberg Blocks by Kadence Blocks | Medium | 4.3 | 2025-01-24 17:25:22 | Deep Dive |
| CVE-2025-24696 | WordPress Gutenberg Blocks and Page Layouts Plugin <= 1.9.6 - Cross Site Request Forgery (CSRF) vulnerability | Shafaet Alam | Attire Blocks | Medium | 4.3 | 2025-01-24 17:25:04 | Deep Dive |
| CVE-2025-24712 | WordPress Radius Blocks – WordPress Gutenberg Blocks Plugin <= 2.1.2 - Cross Site Request Forgery (CSRF) vulnerability | RadiusTheme | Radius Blocks | Medium | 5.4 | 2025-01-24 17:25:02 | Deep Dive |
| CVE-2025-23948 | WordPress Background animation blocks Plugin <= 2.1.5 - Local File Inclusion vulnerability | Webarea | Background animation blocks | High | 8.1 | 2025-01-22 14:29:25 | Deep Dive |
| CVE-2024-12117 | Stackable – Page Builder Gutenberg Blocks <= 3.13.11 - Authenticated (Contributor+) Stored Cross-Site Scripting | bfintal | Stackable – Page Builder Gutenberg Blocks | Medium | 6.4 | 2025-01-22 07:03:53 | Deep Dive |
| CVE-2024-9636 | Post Grid and Gutenberg Blocks 2.2.85 - 2.3.3 - Unauthenticated Privilege Escalation | pickplugins | Post Grid and Gutenberg Blocks – ComboBlocks | Critical | 9.8 | 2025-01-15 09:25:54 | Deep Dive |
| CVE-2024-12304 | Gutenberg Blocks with AI by Kadence WP – Page Builder Features <= 3.4.2 - Authenticated (contributor+) Stored Cross-Site Scripting via Button Link | stellarwp | Kadence Blocks — Page Builder Toolkit for Gutenberg Editor | Medium | 6.4 | 2025-01-11 03:21:03 | Deep Dive |
| CVE-2025-22810 | WordPress Content Blocks Builder plugin <= 2.7.6 - Cross Site Scripting (XSS) vulnerability | Phi Phan | Content Blocks Builder | Medium | 6.5 | 2025-01-09 15:39:06 | Deep Dive |
| CVE-2024-6155 | Greenshift – animation and page builder blocks <= 9.0.0 - Missing Authorization to Authenticated (Subscriber+) Server-Side Request Forgery and Stored Cross-Site Scripting | wpsoul | Greenshift – animation and page builder blocks | Medium | 6.4 | 2025-01-09 11:11:05 | Deep Dive |
| CVE-2024-12045 | Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates <= 5.0.9 - Authenticated (Admin+) Stored Cross-Site Scripting | wpdevteam | Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns | Medium | 4.4 | 2025-01-08 07:18:38 | Deep Dive |
| CVE-2025-22529 | WordPress WE Blocks <= 1.3.5 - Cross Site Scripting (XSS) vulnerability | wordpresteem | WE Blocks | Medium | 6.5 | 2025-01-07 14:57:29 | Deep Dive |
| CVE-2024-56294 | WordPress Nexter Blocks plugin <= 4.0.7 - Broken Access Control vulnerability | POSIMYTH | Nexter Blocks | Medium | 6.4 | 2025-01-07 10:49:11 | Deep Dive |
| CVE-2024-12495 | Bootstrap Blocks for WP Editor v2 <= 2.5.0 - Authenticated (Contributor+) Stored Cross-Site Scripting | virgial | Bootstrap Blocks for WP Editor v2 | Medium | 6.4 | 2025-01-07 06:40:58 | Deep Dive |
| CVE-2024-56258 | WordPress Magazine Blocks plugin <= 1.3.20 - Cross Site Scripting (XSS) vulnerability | BlockArt | Magazine Blocks | Medium | 6.5 | 2025-01-02 12:01:27 | Deep Dive |