Extension WordPress
Vulnérabilités Content Blocks (Custom Post Widget)
Cette page rassemble les failles publiées pour Content Blocks (Custom Post Widget), leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Content Blocks (Custom Post Widget)
6 fiches
Content Blocks (Custom Post Widget) <= 3.3.9 – Authenticated (Author+) Stored Cross-Site Scripting via content_block Shortcode
The Content Blocks (Custom Post Widget) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's content_block shortcode in all versions up to, and including, 3.3.9 due to insufficient input sanitization and output escaping on user…
*-3.3.9
3.4.1
17/04/2026
Content Blocks (Custom Post Widget) <= 3.3.5 – Authenticated (Contributor+) Stored Cross-Site Scripting via content Parameter
The Content Blocks (Custom Post Widget) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘content’ parameter within the plugin's shortcode Content Block in all versions up to, and including, 3.3.5 due to insufficient input sanitization…
*-3.3.5
3.3.6
19/02/2025
Content Blocks (Custom Post Widget) <= 3.3.5 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Content Blocks (Custom Post Widget) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via title tags in all versions up to, and including, 3.3.5 due to insufficient input sanitization and output escaping. This makes it possible…
*-3.3.5
3.3.6
05/09/2024
Content Blocks (Custom Post Widget) <= 3.3.0 – Authenticated (Contributor+) Local File Inclusion via Shortcode
The Content Blocks (Custom Post Widget) plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.3.0 via the plugin's 'content_block' shortcode. This makes it possible for authenticated attackers, with contributor-level access…
*-3.3.0
3.3.1
31/05/2024
Content Blocks (Custom Post Widget) <= 3.3.0 – Authenticated (Contributor+) Stored Cross-Site Scripting via content_block Shortcode
The Content Blocks (Custom Post Widget) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'content_block' shortcode in all versions up to, and including, 3.3.0 due to insufficient input sanitization and output escaping on user…
*-3.3.0
3.3.1
31/05/2024
Content Blocks (Custom Post Widget) <= 3.3.0 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Content Blocks (Custom Post Widget) plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 3.3.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it…
*-3.3.0
3.3.1
07/05/2024
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.