| CVE-2025-11361 | Essential Blocks <= 5.7.1 - Authenticated (Author+) Server-Side Request Forgery | wpdevteam | Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns | Medium | 6.4 | 2025-10-18 04:25:57 | Deep Dive |
| CVE-2025-9626 | Page Blocks <= 1.1.0 - Cross-Site Request Forgery | softwud | Page Blocks | Medium | 4.3 | 2025-10-11 09:28:39 | Deep Dive |
| CVE-2025-9075 | ZoloBlocks – Gutenberg Block Editor Plugin with Advanced Blocks, Dynamic Content, Templates & Patterns <= 2.3.10 - Authenticated (Contributor+) Stored Cross-Site Scripting | bdthemes | ZoloBlocks – Gutenberg Block Editor Plugin with Advanced Blocks, Dynamic Content, Templates & Patterns | Medium | 6.4 | 2025-10-01 03:25:24 | Deep Dive |
| CVE-2025-8624 | Nexa Blocks <= 1.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Google Maps Widget | wpdive | Nexa Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE | Medium | 6.4 | 2025-09-30 03:35:29 | Deep Dive |
| CVE-2025-8566 | GutenBee – Gutenberg Blocks <= 2.18.0 - Authenticated (Contributor+) Stored Cross-Site Scripting | cssigniterteam | GutenBee – Gutenberg Blocks | Medium | 6.4 | 2025-09-30 03:35:24 | Deep Dive |
| CVE-2025-60138 | WordPress SKT Blocks plugin <= 2.6 - Cross Site Scripting (XSS) vulnerability | sonalsinha21 | SKT Blocks | Medium | 6.5 | 2025-09-26 08:31:45 | Deep Dive |
| CVE-2025-59561 | WordPress Smart Blocks Plugin <= 2.4 - Broken Access Control Vulnerability | hashthemes | Smart Blocks | Medium | 4.3 | 2025-09-22 18:26:03 | Deep Dive |
| CVE-2025-59573 | WordPress Cozy Blocks Plugin <= 2.1.29 - Content Injection Vulnerability | CozyThemes | Cozy Blocks | Medium | 5.3 | 2025-09-22 18:25:57 | Deep Dive |
| CVE-2025-58258 | WordPress Lazy Blocks Plugin <= 4.1.0 - Broken Access Control Vulnerability | nK | Lazy Blocks | Medium | 4.3 | 2025-09-22 18:23:23 | Deep Dive |
| CVE-2025-9992 | Ghost Kit <= 3.4.3 - Authenticated (Contributor+) Stored Cross-Site Scripting | nko | Ghost Kit – Page Builder Blocks, Motion Effects & Extensions | Medium | 6.4 | 2025-09-18 09:31:28 | Deep Dive |
| CVE-2025-42915 | Missing Authorization Check in Fiori app (Manage Payment Blocks) | SAP_SE | Fiori app (Manage Payment Blocks) | Medium | 5.4 | 2025-09-09 02:06:33 | Deep Dive |
| CVE-2025-8722 | Content Views <= 4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Grid and List Widgets | pt-guy | Content Views – Post Grid & Filter, Recent Posts, Category Posts … (Shortcode, Gutenberg Blocks, and Widgets for Elementor) | Medium | 6.4 | 2025-09-06 03:22:35 | Deep Dive |
| CVE-2025-9378 | Vayu Blocks <= 1.3.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Block Attributes | themehunk | Vayu Blocks – Website Builder for the Block Editor | Medium | 6.4 | 2025-09-03 06:43:10 | Deep Dive |
| CVE-2025-54733 | WordPress All Bootstrap Blocks Plugin <= 1.3.28 - Broken Access Control Vulnerability | all_bootstrap_blocks | All Bootstrap Blocks | Medium | 6.5 | 2025-08-28 12:37:39 | Deep Dive |
| CVE-2025-8607 | SlingBlocks – Gutenberg Blocks by FunnelKit (Formerly WooFunnels) <= 1.6.0 - Authenticated (Contributor+) Stored Cross-Site Scripting | amans2k | SlingBlocks – Gutenberg Blocks by FunnelKit (Formerly WooFunnels) | Medium | 6.4 | 2025-08-21 05:28:15 | Deep Dive |
| CVE-2025-53207 | WordPress WP Travel Gutenberg Blocks plugin <= 3.9.0 - Local File Inclusion Vulnerability | WP Travel | WP Travel Gutenberg Blocks | High | 8.1 | 2025-08-20 08:03:19 | Deep Dive |
| CVE-2025-54007 | WordPress Post Grid and Gutenberg Blocks Plugin <= 2.3.11 - PHP Object Injection Vulnerability | PickPlugins | Post Grid and Gutenberg Blocks | High | 8.8 | 2025-08-20 08:03:05 | Deep Dive |
| CVE-2025-8567 | Nexter Blocks <= 4.5.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets | posimyththemes | Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder | Medium | 6.4 | 2025-08-19 08:24:16 | Deep Dive |
| CVE-2024-8393 | Woocommerce Blocks – Woolook <= 1.7.0 - Authenticated (Admin+) Local File Inclusion | delabon | Woocommerce Blocks – Woolook | Medium | 6.6 | 2025-08-16 03:38:52 | Deep Dive |
| CVE-2025-5844 | Radius Blocks <= 2.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via subHeadingTagName Parameter | techlabpro1 | Radius Blocks – WordPress Gutenberg Blocks | Medium | 6.4 | 2025-08-15 08:25:42 | Deep Dive |