| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2024-56246 | WordPress Nexter Blocks plugin <= 4.0.4 - Cross Site Scripting (XSS) vulnerability | POSIMYTH | Nexter Blocks | Medium | 6.5 | 2025-01-02 12:01:21 | Deep Dive |
| CVE-2024-56245 | WordPress Premium Blocks plugin <= 2.1.42 - Cross Site Scripting (XSS) vulnerability | Leap13 | Premium Blocks – Gutenberg Blocks for WordPress | Medium | 6.5 | 2025-01-02 12:01:20 | Deep Dive |
| CVE-2024-12268 | Responsive Blocks – WordPress Gutenberg Blocks <= 1.9.7 - Authenticated (Contributor+) Stored Cross-Site Scripting | cyberchimps | Responsive Blocks – Page Builder for Blocks & Patterns | Medium | 6.4 | 2024-12-24 11:09:49 | Deep Dive |
| CVE-2024-54272 | WordPress Radius Blocks plugin <= 2.1.2 - Cross Site Scripting (XSS) vulnerability | RadiusTheme | Radius Blocks | Medium | 6.5 | 2024-12-13 14:24:48 | Deep Dive |
| CVE-2024-54264 | WordPress Shortcodes Blocks Creator Ultimate plugin <= 2.2.0 - Reflected Cross Site Scripting (XSS) vulnerability | cmorillas1 | Shortcodes Blocks Creator Ultimate | High | 7.1 | 2024-12-13 14:24:43 | Deep Dive |
| CVE-2024-54256 | WordPress Easy Blocks pro plugin <= 1.0.21 - Broken Access Control vulnerability | Seerox | Easy Blocks pro | High | 7.1 | 2024-12-13 14:24:40 | Deep Dive |
| CVE-2022-47594 | WordPress Essential Blocks for Gutenberg plugin <= 3.8.5 - Broken Access Control | WPDeveloper | Essential Blocks for Gutenberg | Medium | 6.5 | 2024-12-13 14:22:12 | Deep Dive |
| CVE-2024-10678 | Ultimate Blocks < 3.2.4 - Contributor+ Stored XSS | Unknown | Ultimate Blocks | 中危 | - | 2024-12-13 06:00:02 | Deep Dive |
| CVE-2024-12581 | Kadence Blocks <= 3.2.53 - Authenticated (Admin+) Stored Cross-Site Scripting | stellarwp | Kadence Blocks — Page Builder Toolkit for Gutenberg Editor | Medium | 4.4 | 2024-12-13 05:24:49 | Deep Dive |
| CVE-2024-11181 | Greenshift – animation and page builder blocks <= 9.9.9.3 - Authenticated (Contributor+) Post Disclosure | wpsoul | Greenshift – animation and page builder blocks | Medium | 4.3 | 2024-12-12 06:46:33 | Deep Dive |
| CVE-2024-10637 | Kadence Blocks < 3.2.54 - Admin+ Stored XSS | Unknown | Gutenberg Blocks with AI by Kadence WP | 中危 | - | 2024-12-12 06:00:19 | Deep Dive |
| CVE-2024-10124 | Vayu Blocks – Gutenberg Blocks for WordPress & WooCommerce <= 1.1.1 - Missing Authorization to Unauthenticated Arbitrary Plugin Installation/Activation | themehunk | Vayu Blocks – Website Builder for the Block Editor | Critical | 9.8 | 2024-12-12 05:24:22 | Deep Dive |
| CVE-2024-11914 | Gutenberg Blocks and Page Layouts – Attire Blocks <= 1.9.5 - Authenticated (Contributor+) Stored Cross-Site Scripting | shafayat-alam | Gutenberg Blocks and Page Layouts – Attire Blocks | Medium | 6.4 | 2024-12-12 03:23:07 | Deep Dive |
| CVE-2023-47760 | WordPress Essential Blocks plugin <= 4.2.0 - Broken Access Control vulnerability | WPDeveloper | Essential Blocks for Gutenberg | 中危 | - | 2024-12-09 11:30:52 | Deep Dive |
| CVE-2023-51360 | WordPress Essential Blocks plugin <= 4.2.0 - Multiple Subscriber+ Broken Access Control vulnerability | WPDeveloper | Essential Blocks for Gutenberg | 中危 | - | 2024-12-09 11:29:49 | Deep Dive |
| CVE-2023-51359 | WordPress Essential Blocks plugin <= 4.2.0 - Multiple Contributor+ Broken Access Control vulnerability | WPDeveloper | Essential Blocks for Gutenberg | 中危 | - | 2024-12-09 11:29:48 | Deep Dive |
| CVE-2024-12167 | Shortcodes Blocks Creator Ultimate <= 2.2.0 - Reflected Cross-Site Scripting via _wpnonce | cmorillas1 | Shortcodes Blocks Creator Ultimate | Medium | 6.1 | 2024-12-07 01:45:52 | Deep Dive |
| CVE-2024-12166 | Shortcodes Blocks Creator Ultimate <= 2.2.0 - Reflected Cross-Site Scripting via 'page' | cmorillas1 | Shortcodes Blocks Creator Ultimate | Medium | 6.1 | 2024-12-07 01:45:50 | Deep Dive |
| CVE-2024-53794 | WordPress Arkhe Blocks plugin <= 2.27.0 - Cross Site Scripting (XSS) vulnerability | Ryo | Arkhe Blocks | Medium | 6.5 | 2024-12-06 13:07:36 | Deep Dive |
| CVE-2024-53824 | WordPress All Bootstrap Blocks plugin <= 1.3.20 - Local File Inclusion vulnerability | all_bootstrap_blocks | All Bootstrap Blocks | High | 7.5 | 2024-12-06 13:05:56 | Deep Dive |