| CVE-2025-14158 | Coding Blocks <= 1.1.0 - Cross-Site Request Forgery to Settings Update | octagonsimon | Coding Blocks | Medium | 4.3 | 2025-12-12 03:20:46 | Deep Dive |
| CVE-2025-14119 | App Landing Template Blocks for WPBakery Page Builder <= 2.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes | themebon | App Landing Template Blocks for WPBakery (Visual Composer) Page Builder | Medium | 6.4 | 2025-12-12 03:20:46 | Deep Dive |
| CVE-2025-62090 | WordPress Gutenverse News – Advanced News Magazine Blog Gutenberg Blocks Addons plugin <= 3.0.2 - Broken Access Control vulnerability | Jegstudio | Gutenverse News – Advanced News Magazine Blog Gutenberg Blocks Addons | - | - | 2025-12-09 14:52:20 | Deep Dive |
| CVE-2025-13697 | BlockArt Blocks – Gutenberg Blocks, Page Builder Blocks ,WordPress Block Plugin, Sections & Template Library <= 2.2.13 - Authenticated (Contributor+) Stored Cross-Site Scripting via `timestamp` Attribute | wpblockart | BlockArt Blocks – Gutenberg Blocks, Page Builder Blocks ,WordPress Block Plugin, Sections & Template Library | Medium | 6.4 | 2025-12-02 01:51:57 | Deep Dive |
| CVE-2025-8605 | Gutenify - Visual Site Builder Blocks & Site Templates <= 1.5.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Count Up block | codeyatri | Gutenify – Visual Site Builder Blocks & Site Templates. | Medium | 6.4 | 2025-11-18 08:27:34 | Deep Dive |
| CVE-2025-12182 | Qi Blocks <= 1.4.3 - Missing Authorization to Arbitrary Attachment Resize | qodeinteractive | Qi Blocks | Medium | 4.3 | 2025-11-15 03:27:01 | Deep Dive |
| CVE-2025-64383 | WordPress Qi Blocks plugin <= 1.4.3 - Cross Site Scripting (XSS) vulnerability | Qode | Qi Blocks | 中危 | - | 2025-11-13 09:24:36 | Deep Dive |
| CVE-2025-12880 | Progress Bar Blocks for Gutenberg <= 1.0.0 - Authenticated (Author+) Stored Cross-Site Scripting via SVG | jobayer534 | Progress Bar Blocks for Gutenberg | Medium | 5.4 | 2025-11-11 03:30:36 | Deep Dive |
| CVE-2025-11162 | Spectra <= 2.19.14 - Authenticated (Contributor+) Stored Cross-Site Scripting via Custom CSS | brainstormforce | Spectra Gutenberg Blocks – Website Builder for the Block Editor | Medium | 6.4 | 2025-11-05 04:36:58 | Deep Dive |
| CVE-2025-10896 | Multiple Plugins <= Multiple Versions - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Upload | litonice13 | Image Comparison Addon for Elementor | High | 8.8 | 2025-11-04 04:27:13 | Deep Dive |
| CVE-2025-11841 | Greenshift – animation and page builder blocks <= 12.2.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Chart Data Attributes | wpsoul | Greenshift – animation and page builder blocks | Medium | 6.4 | 2025-11-04 01:50:26 | Deep Dive |
| CVE-2025-12180 | Qi Blocks <= 1.4.3 - Missing Authorization to Authenticated (Contributor+) Plugin Settings Update | qodeinteractive | Qi Blocks | Medium | 4.3 | 2025-11-01 05:40:22 | Deep Dive |
| CVE-2025-62924 | WordPress Post Grid and Gutenberg Blocks plugin <= 2.3.17 - Broken Access Control vulnerability | PickPlugins | Post Grid and Gutenberg Blocks | Medium | 6.5 | 2025-10-27 01:33:59 | Deep Dive |
| CVE-2025-10580 | Widget Options – The #1 WordPress Widget & Block Control Plugin <= 4.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting | marketingfire | Widget Options – Advanced Conditional Visibility for Gutenberg Blocks & Classic Widgets | Medium | 6.4 | 2025-10-25 06:49:23 | Deep Dive |
| CVE-2025-8588 | Gutenberg Blocks – PublishPress Blocks Controls, Visibility, Reusable Blocks <= 3.3.4 - Authenticated (Contributor+) Stored Cross-Site Scripting | publishpress | PublishPress Blocks – Block Controls, Block Visibility, Block Permissions | Medium | 6.4 | 2025-10-25 05:31:21 | Deep Dive |
| CVE-2025-12134 | ZoloBlocks <= 2.3.11 - Missing Authorization to Unauthenticated Popup Enable/Disable | bdthemes | ZoloBlocks – Gutenberg Block Editor Plugin with Advanced Blocks, Dynamic Content, Templates & Patterns | Medium | 5.3 | 2025-10-24 09:23:31 | Deep Dive |
| CVE-2025-62063 | WordPress WP Travel Gutenberg Blocks plugin <= 3.9.2 - Cross Site Scripting (XSS) vulnerability | WP Travel | WP Travel Gutenberg Blocks | - | - | 2025-10-22 14:32:53 | Deep Dive |
| CVE-2025-62019 | WordPress Recipe Card Blocks for Gutenberg & Elementor plugin <= 3.4.8 - Broken Access Control vulnerability | WPZOOM | Recipe Card Blocks for Gutenberg & Elementor | - | - | 2025-10-22 14:32:49 | Deep Dive |
| CVE-2025-49929 | WordPress Ultimate Blocks plugin <= 3.3.6 - Cross Site Scripting (XSS) vulnerability | Ultimate Blocks | Ultimate Blocks | - | - | 2025-10-22 14:32:15 | Deep Dive |
| CVE-2025-11270 | Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns <= 5.7.1 - Authenticated (Contributor+) Stored Cross-Site Scripting | wpdevteam | Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns | Medium | 6.4 | 2025-10-18 06:42:48 | Deep Dive |