| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2025-2918 | Ultimate Blocks – WordPress Blocks Plugin <= 3.3.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets | ultimateblocks | Ultimate Blocks – 25+ Gutenberg Blocks for Block Editor | Medium | 6.4 | 2025-06-10 11:22:52 | Deep Dive |
| CVE-2025-48130 | WordPress Spice Blocks plugin <= 2.0.7.4 - Arbitrary File Download vulnerability | spicethemes | Spice Blocks | High | 7.5 | 2025-06-09 15:54:01 | Deep Dive |
| CVE-2025-30951 | WordPress BlockStrap Page Builder - Bootstrap Blocks plugin <= 0.1.36 - Cross Site Scripting (XSS) Vulnerability | Stiofan | BlockStrap Page Builder - Bootstrap Blocks | Medium | 6.5 | 2025-06-06 12:54:12 | Deep Dive |
| CVE-2025-30952 | WordPress Nexa Blocks plugin <= 1.1.0 - Cross Site Scripting (XSS) Vulnerability | wpdive | Nexa Blocks | Medium | 6.5 | 2025-06-06 12:54:11 | Deep Dive |
| CVE-2025-30976 | WordPress Nexa Blocks plugin <= 1.1.1 - Server Side Request Forgery (SSRF) vulnerability | wpdive | Nexa Blocks | Medium | 4.9 | 2025-06-06 12:54:07 | Deep Dive |
| CVE-2025-4420 | Vayu Blocks <= 1.3.1 - Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting via containerWidth Parameter | themehunk | Vayu Blocks – Website Builder for the Block Editor | Medium | 6.4 | 2025-06-03 08:21:53 | Deep Dive |
| CVE-2025-5292 | Element Pack Addons for Elementor – Best Elementor addons with Ready Templates, Blocks, Widgets and WooCommerce Builder <= 5.11.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting | bdthemes | Element Pack – Widgets, Templates & Addons for Elementor | Medium | 6.4 | 2025-05-31 06:40:57 | Deep Dive |
| CVE-2025-4682 | Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates <= 5.4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Slider and Post Carousel Widgets | wpdevteam | Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns | Medium | 6.4 | 2025-05-27 01:48:49 | Deep Dive |
| CVE-2025-48270 | WordPress SKT Blocks plugin <= 2.2 - Cross Site Scripting (XSS) Vulnerability | sonalsinha21 | SKT Blocks | Medium | 6.5 | 2025-05-19 14:45:25 | Deep Dive |
| CVE-2025-48234 | WordPress Ultimate Blocks plugin <= 3.3.0 - Cross Site Scripting (XSS) Vulnerability | Ultimate Blocks | Ultimate Blocks | Medium | 6.5 | 2025-05-19 14:44:50 | Deep Dive |
| CVE-2025-1627 | Qi Blocks < 1.4 - Contributor+ Stored XSS via ToC Block | Unknown | Qi Blocks | - | - | 2025-05-19 06:00:05 | Deep Dive |
| CVE-2025-1625 | Qi Blocks < 1.4 - Contributor+ Stored XSS via Counter Block | Unknown | Qi Blocks | - | - | 2025-05-19 06:00:04 | Deep Dive |
| CVE-2025-1626 | Qi Blocks < 1.4 - Contributor+ Stored XSS vi Countdown Block | Unknown | Qi Blocks | - | - | 2025-05-19 06:00:04 | Deep Dive |
| CVE-2024-3901 | Genesis Blocks <= 3.1.3 - Contributor+ Stored XSS | Unknown | Genesis Blocks | - | - | 2025-05-15 20:09:45 | Deep Dive |
| CVE-2025-3605 | Frontend Login and Registration Blocks <= 1.1.1 - Unauthenticated Privilege Escalation via Account Takeover | arkenon | Login, Registration and Lost Password Blocks | Critical | 9.8 | 2025-05-09 06:42:35 | Deep Dive |
| CVE-2025-47493 | WordPress Ultimate Blocks plugin <= 3.2.9 - Cross Site Scripting (XSS) Vulnerability | Ultimate Blocks | Ultimate Blocks | Medium | 6.5 | 2025-05-07 14:19:53 | Deep Dive |
| CVE-2025-47485 | WordPress Cozy Blocks plugin <= 2.1.22 - Broken Access Control Vulnerability | CozyThemes | Cozy Blocks | Medium | 5.3 | 2025-05-07 14:19:50 | Deep Dive |
| CVE-2025-1458 | Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid, Carousel and Remote Arrows) <= 5.10.29 - Authenticated (Contributor+) Stored Cross-Site Scripting | bdthemes | Element Pack – Widgets, Templates & Addons for Elementor | Medium | 6.4 | 2025-04-26 05:34:23 | Deep Dive |
| CVE-2025-3607 | Frontend Login and Registration Blocks <= 1.0.8 - Authenticated (Subscriber+) Privilege Escalation via Password Reset | arkenon | Login, Registration and Lost Password Blocks | High | 8.8 | 2025-04-24 08:23:50 | Deep Dive |
| CVE-2025-46235 | WordPress SKT Blocks – Gutenberg based Page Builder plugin <= 2.0 - Cross Site Scripting (XSS) Vulnerability | sonalsinha21 | SKT Blocks | Medium | 6.5 | 2025-04-22 09:53:25 | Deep Dive |