| CVE-2024-3936 | The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid <= 7.6.1 - Missing Authorization | techlabpro1 | The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid | Medium | 4.3 | 2024-05-02 16:52:52 | Deep Dive |
| CVE-2024-2273 | Gutenberg Blocks by Kadence Blocks – Page Builder Features <= 3.2.34 - Authenticated (Contributor+) Stored Cross-Site Scripting | stellarwp | Kadence Blocks — Page Builder Toolkit for Gutenberg Editor | Medium | 6.4 | 2024-05-02 16:52:49 | Deep Dive |
| CVE-2024-3725 | Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE <= 2.6.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'titleTag' | themeisle | Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE | Medium | 6.4 | 2024-05-02 16:52:41 | Deep Dive |
| CVE-2024-3588 | Getwid – Gutenberg Blocks <= 2.0.7 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via 'Countdown' | jetmonsters | Getwid – Gutenberg Blocks | Medium | 6.4 | 2024-05-02 16:52:36 | Deep Dive |
| CVE-2024-0615 | Content Control <= 2.1.0 - Missing Authorization to Sensitive Information Exposure | danieliser | Content Control – The Ultimate Content Restriction Plugin! Restrict Content, Create Conditional Blocks & More | Medium | 5.3 | 2024-05-02 16:52:28 | Deep Dive |
| CVE-2024-3107 | Spectra – WordPress Gutenberg Blocks <= 2.12.6 - Authenticated (Contributor+) Path Traversal | brainstormforce | Spectra Gutenberg Blocks – Website Builder for the Block Editor | Medium | 4.3 | 2024-05-02 16:51:46 | Deep Dive |
| CVE-2024-3929 | Content Views – Post Grid & Filter, Recent Posts, Category Posts, & More (Gutenberg Blocks and Shortcode) <= 3.7.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Widget Post Overlay | pt-guy | Content Views – Post Grid & Filter, Recent Posts, Category Posts … (Shortcode, Gutenberg Blocks, and Widgets for Elementor) | Medium | 6.4 | 2024-04-25 07:33:58 | Deep Dive |
| CVE-2024-2761 | Genesis Blocks < 3.1.3 - Contributor+ Stored XSS | Unknown | Genesis Blocks | 高危 | - | 2024-04-19 05:00:02 | Deep Dive |
| CVE-2024-3818 | Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates <= 4.5.9 - Authenticated (Contributor+) DOM-Based Cross-Site Scripting via "Social Icons" Block | wpdevteam | Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns | Medium | 5.4 | 2024-04-19 02:34:43 | Deep Dive |
| CVE-2024-2729 | Otter Blocks < 2.6.6 - Contributor+ Stored XSS | Unknown | Otter Blocks | 中危 | - | 2024-04-18 05:00:02 | Deep Dive |
| CVE-2024-0881 | Combo Blocks < 2.2.76 - Unauthenticated Password Protected Posts Access | Unknown | Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel | - | - | 2024-04-11 15:36:31 | Deep Dive |
| CVE-2024-3344 | Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE <= 2.6.8 - Authenticated (Author+) Limited File Upload to Stored Cross-Site Scripting | themeisle | Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE | Medium | 6.4 | 2024-04-11 11:03:52 | Deep Dive |
| CVE-2024-3343 | Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE <= 2.6.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Block Attributes | themeisle | Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE | Medium | 6.4 | 2024-04-11 11:03:51 | Deep Dive |
| CVE-2024-2039 | Stackable – Page Builder Gutenberg Blocks <= 3.12.11 - Authenticated(Contributor+) Stored Cross-Site Scripting via Posts Block | bfintal | Stackable – Page Builder Gutenberg Blocks | Medium | 6.4 | 2024-04-09 18:59:27 | Deep Dive |
| CVE-2023-6486 | Spectra – WordPress Gutenberg Blocks <= 2.10.3 - Authenticated(Contributor+) Cross-Site Scripting via Custom CSS | brainstormforce | Spectra Gutenberg Blocks – Website Builder for the Block Editor | Medium | 6.4 | 2024-04-09 18:59:25 | Deep Dive |
| CVE-2024-1999 | Gutenberg Blocks by Kadence Blocks – Page Builder Features <= 3.2.25 - Authenticated (Contributor+) Stored Cross-Site Scripting via Testimonial Widget | stellarwp | Kadence Blocks — Page Builder Toolkit for Gutenberg Editor | Medium | 6.4 | 2024-04-09 18:59:16 | Deep Dive |
| CVE-2023-6964 | Gutenberg Blocks by Kadence Blocks – Page Builder Features <= 3.1.26 - Authenticated(Contributor+) Server-Side Request Forgery (SSRF) | stellarwp | Kadence Blocks — Page Builder Toolkit for Gutenberg Editor | High | 8.5 | 2024-04-09 18:59:15 | Deep Dive |
| CVE-2024-0598 | Gutenberg Blocks by Kadence Blocks <= 3.2.17 - Authenticated(Editor+) Stored Cross-Site Scripting via Contact Form Message Settings | stellarwp | Kadence Blocks — Page Builder Toolkit for Gutenberg Editor | Medium | 4.4 | 2024-04-09 18:59:07 | Deep Dive |
| CVE-2024-1948 | Getwid – Gutenberg Blocks <= 2.0.5 - Authenticated(Contributor+) Stored Cross-Site Scripting via Block Content | jetmonsters | Getwid – Gutenberg Blocks | Medium | 6.4 | 2024-04-09 18:58:55 | Deep Dive |
| CVE-2024-2226 | Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE <= 2.6.4 - Authenticated (Contributor+) Stored Cross-Site Scripting | themeisle | Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE | Medium | 6.4 | 2024-04-09 18:58:38 | Deep Dive |