All 3 CVE vulnerabilities found in Vayu Blocks – Website Builder for the Block Editor, with AI-generated Chinese analysis, references, and POCs.
Vendor: themehunk
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2025-9378 | Vayu Blocks <= 1.3.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Block Attributes CWE-79 | 6.4 | Medium | 2025-09-03 |
| CVE-2025-4420 | Vayu Blocks <= 1.3.1 - Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting via containerWidth Parameter CWE-79 | 6.4 | Medium | 2025-06-03 |
| CVE-2024-10124 | Vayu Blocks – Gutenberg Blocks for WordPress & WooCommerce <= 1.1.1 - Missing Authorization to Unauthenticated Arbitrary Plugin Installation/Activation CWE-284 | 9.8 | Critical | 2024-12-12 |
All 3 known CVE vulnerabilities affecting Vayu Blocks – Website Builder for the Block Editor with full Chinese analysis, references, and POCs where available.