Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Crocoblock — Vulnerabilities & Security Advisories 97

Browse all 97 CVE security advisories affecting Crocoblock. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Crocoblock operates as a provider of WordPress plugins and extensions, primarily facilitating advanced data management, dynamic content creation, and e-commerce functionality for website builders. Historically, its software portfolio has been associated with a significant volume of security flaws, currently totaling 87 recorded Common Vulnerabilities and Exposures. The most prevalent vulnerability classes include Cross-Site Scripting (XSS), SQL Injection, and Remote Code Execution (RCE), often stemming from insufficient input validation and improper access controls within plugin endpoints. Additionally, privilege escalation issues have been documented, allowing unauthorized users to perform administrative actions. While no single catastrophic breach has defined the company’s public history, the high frequency of disclosed CVEs indicates systemic weaknesses in code review and security testing processes. These recurring issues highlight the risks inherent in complex WordPress ecosystems where third-party extensions may lack rigorous security auditing, leaving user data and server integrity vulnerable to exploitation.

Found 13 results / 97 Clear Filters
CVE ID Title CVSS Severity Published
CVE-2026-24958 WordPress JetElements For Elementor plugin <= 2.7.12.2 - Cross Site Scripting (XSS) vulnerability — JetElements For Elementor CWE-79 6.5 Medium 2026-02-03
CVE-2025-64355 WordPress JetElements For Elementor plugin <= 2.7.12 - Cross Site Scripting (XSS) vulnerability — JetElements For Elementor CWE-79 6.5 Medium 2025-12-18
CVE-2025-49939 WordPress JetElements For Elementor plugin <= 2.7.8 - Cross Site Scripting (XSS) vulnerability — JetElements For Elementor CWE-79 6.5 Medium 2025-10-22
CVE-2025-53983 WordPress JetElements For Elementor <= 2.7.7 - Sensitive Data Exposure Vulnerability — JetElements For Elementor CWE-201 6.5 Medium 2025-08-20
CVE-2025-55714 WordPress JetElements For Elementor Plugin <= 2.7.9 - Cross Site Scripting (XSS) Vulnerability — JetElements For Elementor CWE-79 6.5 Medium 2025-08-14
CVE-2025-53982 WordPress JetElements For Elementor plugin <= 2.7.7 - Cross Site Scripting (XSS) Vulnerability — JetElements For Elementor CWE-79 6.5 Medium 2025-07-16
CVE-2025-39447 WordPress JetElements For Elementor plugin <= 2.7.4.1 - Broken Access Control Vulnerability — JetElements For Elementor CWE-862 7.5 High 2025-05-19
CVE-2025-39448 WordPress JetElements For Elementor plugin <= 2.7.4.1 - Cross Site Scripting (XSS) vulnerability — JetElements For Elementor CWE-79 6.5 Medium 2025-05-19
CVE-2023-48759 WordPress JetElements For Elementor plugin <= 2.6.13 - Unauthenticated Arbitrary Attachment Download vulnerability — JetElements For Elementor CWE-862 7.5 High 2024-06-19
CVE-2023-48760 WordPress JetElements For Elementor plugin <= 2.6.13 - Unauthenticated Broken Access Control vulnerability — JetElements For Elementor CWE-862 8.2 High 2024-06-19
CVE-2023-48761 WordPress JetElements For Elementor plugin <= 2.6.13 - Broken Access Control vulnerability — JetElements For Elementor CWE-862 6.3 Medium 2024-06-19
CVE-2023-39157 WordPress JetElements For Elementor Plugin <= 2.6.10 is vulnerable to Remote Code Execution (RCE) — JetElements For Elementor CWE-94 9.0 Critical 2023-12-31
CVE-2023-48762 WordPress JetElements For Elementor Plugin <= 2.6.13 is vulnerable to Cross Site Request Forgery (CSRF) — JetElements For Elementor CWE-352 6.3 Medium 2023-12-18

This page lists every published CVE security advisory associated with Crocoblock. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.