| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2024-0612 | Content Views <= 3.6.2 - Authenticated(Administrator+) Stored Cross-Site Scripting via settings | pt-guy | Content Views – Post Grid & Filter, Recent Posts, Category Posts … (Shortcode, Gutenberg Blocks, and Widgets for Elementor) | Medium | 4.4 | 2024-02-05 21:21:57 | Deep Dive |
| CVE-2023-6959 | Getwid – Gutenberg Blocks <= 2.0.4 - Missing Authorization to Recaptcha API Key Modification | jetmonsters | Getwid – Gutenberg Blocks | Medium | 4.3 | 2024-02-05 21:21:50 | Deep Dive |
| CVE-2024-22136 | WordPress Droit Elementor Addons Plugin <= 3.1.5 is vulnerable to Cross Site Request Forgery (CSRF) | DroitThemes | Droit Elementor Addons – Widgets, Blocks, Templates Library For Elementor Builder | Medium | 4.3 | 2024-01-31 13:53:10 | Deep Dive |
| CVE-2023-6623 | Essential Blocks < 4.4.3 - Unauthenticated Local File Inclusion | Unknown | Essential Blocks | 超危 | - | 2024-01-15 15:10:40 | Deep Dive |
| CVE-2023-7071 | Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates <= 4.4.6 - Authenticated (Contributor+) Stored Cross-Site Scripting | wpdevteam | Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns | Medium | 6.4 | 2024-01-11 08:33:10 | Deep Dive |
| CVE-2023-6645 | Post Grid Combo – 36+ Gutenberg Blocks <= 2.2.64 - Authenticated (Contributor+) Cross-Site Scripting | pickplugins | Post Grid | Medium | 6.4 | 2024-01-11 08:32:50 | Deep Dive |
| CVE-2023-6636 | Greenshift – animation and page builder blocks <= 7.6.2 - Authenticated (Administrator+) Arbitrary File Upload | wpsoul | Greenshift – animation and page builder blocks | High | 7.2 | 2024-01-11 08:32:41 | Deep Dive |
| CVE-2023-51378 | WordPress Rise Blocks Plugin <= 3.1 is vulnerable to Cross Site Request Forgery (CSRF) | Rise Themes | Rise Blocks – A Complete Gutenberg Page Builder | Medium | 5.4 | 2023-12-29 12:08:17 | Deep Dive |
| CVE-2023-49148 | WordPress Affiliate Booster – Pros & Cons, Notice, and CTA Blocks for Affiliates Plugin <= 3.0.5 is vulnerable to Cross Site Request Forgery (CSRF) | Kulwant Nagi | Affiliate Booster – Pros & Cons, Notice, and CTA Blocks for Affiliates | Medium | 5.4 | 2023-12-18 22:08:12 | Deep Dive |
| CVE-2023-49833 | WordPress Spectra Plugin <= 2.7.9 is vulnerable to Cross Site Scripting (XSS) | Brainstorm Force | Spectra – WordPress Gutenberg Blocks | Medium | 6.5 | 2023-12-14 14:26:59 | Deep Dive |
| CVE-2023-40211 | WordPress Post Grid Plugin <= 2.2.50 is vulnerable to Sensitive Data Exposure | PickPlugins | Post Grid Combo – 36+ Gutenberg Blocks | High | 7.5 | 2023-11-30 15:03:24 | Deep Dive |
| CVE-2023-47777 | WordPress WooCommerce and WooCommerce Blocks plugins - Auth. Cross-Site Scripting (XSS) vulnerability | Automattic | WooCommerce | Medium | 6.5 | 2023-11-30 11:56:54 | Deep Dive |
| CVE-2023-5706 | VK Blocks <= 1.63.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Block | vektor-inc | VK Blocks | Medium | 6.4 | 2023-11-22 15:33:19 | Deep Dive |
| CVE-2023-27611 | WordPress Reusable Blocks Extended Plugin <= 0.9 is vulnerable to Cross Site Request Forgery (CSRF) | audrasjb | Reusable Blocks Extended | Medium | 5.4 | 2023-11-12 22:35:55 | Deep Dive |
| CVE-2023-5745 | Reusable Text Blocks <= 1.5.3 - Authenticated (Author+) Stored Cross-Site Scripting via Shortcode | richardgabriel | Reusable Text Blocks | Medium | 5.5 | 2023-10-24 13:52:58 | Deep Dive |
| CVE-2023-4386 | Essential Blocks <= 4.2.0 - Unauthenticated PHP Object Injection via queries | wpdevteam | Essential Blocks Pro | High | 8.1 | 2023-10-20 07:29:28 | Deep Dive |
| CVE-2023-4402 | Essential Blocks <= 4.2.0 - Unauthenticated PHP Object Injection via products | wpdevteam | Essential Blocks Pro | High | 8.1 | 2023-10-20 06:35:11 | Deep Dive |
| CVE-2023-41732 | WordPress CP Blocks Plugin <= 1.0.20 is vulnerable to Cross Site Request Forgery (CSRF) | CodePeople | CP Blocks | Medium | 5.4 | 2023-10-06 14:44:43 | Deep Dive |
| CVE-2023-44262 | WordPress Blocks Plugin <= 1.6.41 is vulnerable to Cross Site Scripting (XSS) | Renzo Johnson | Blocks | Medium | 5.9 | 2023-10-02 09:55:30 | Deep Dive |
| CVE-2023-35047 | WordPress All Bootstrap Blocks Plugin <= 1.3.6 is vulnerable to Cross Site Request Forgery (CSRF) | AREOI | All Bootstrap Blocks | Medium | 4.3 | 2023-07-11 11:14:46 | Deep Dive |