Extension WordPress
Vulnérabilités bBlocks – Essential Gutenberg Blocks & Patterns Collection
Cette page rassemble les failles publiées pour bBlocks – Essential Gutenberg Blocks & Patterns Collection, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de bBlocks – Essential Gutenberg Blocks & Patterns Collection
6 fiches
Freemius <= 2.10.1 – Reflected DOM-Based Cross-Site Scripting via url Parameter
Multiple plugins and/or themes for WordPress are vulnerable to Reflected Cross-Site Scripting via the url parameter in various versions due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…
*-1.9.8
2.0.19
30/04/2026
bBlocks – Essential Gutenberg Blocks & Patterns Collection < 2.0.30 – Missing Authorization
The bBlocks – Essential Gutenberg Blocks & Patterns Collection plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to 2.0.30 (exclusive). This makes it possible for…
[*, 2.0.30)
2.0.30
23/04/2026
bBlocks – Essential Gutenberg Blocks & Patterns Collection <= 2.0.31 – Authenticated (Contributor+) Privilege Escalation
The bBlocks – Essential Gutenberg Blocks & Patterns Collection plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.0.31. This makes it possible for authenticated attackers, with Contributor-level access and above, to…
*-2.0.31
2.0.32
16/04/2026
B Blocks <= 2.0.5 – Authenticated (Contributor+) Stored Cross-Site Scripting
The B Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.0.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and…
*-2.0.5
2.0.6
14/08/2025
B Blocks <= 2.0.6 – Missing Authorization to Unauthenticated Privilege Escalation via rgfr_registration Function
The B Blocks plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization and improper input validation within the rgfr_registration() function in all versions up to, and including, 2.0.6. This makes it possible for unauthenticated attackers…
*-2.0.6
2.0.7
11/08/2025
B Blocks – The ultimate block collection <= 2.0.0 – Authenticated (Contributor+) Stored Cross-Site Scripting
The B Blocks – The ultimate block collection plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…
*-2.0.0
2.0.1
04/04/2025
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.