Extension WordPress
Vulnérabilités Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns
Cette page rassemble les failles publiées pour Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns
31 fiches
Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns <= 6.1.4 – Authenticated (Contributor+) Stored Cross-Site Scripting via 'configurablePrefix' Block Attribute
The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'configurablePrefix' Block Attribute in all versions up to, and including, 6.1.4 due to insufficient input…
*-6.1.4
6.2.0
24/06/2026
Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns <= 6.1.3 – Authenticated (Author+) Server-Side Request Forgery
The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6.1.3 via the `save_ai_generated_image()` function. This makes it possible for…
*-6.1.3
6.1.4
04/06/2026
Gutenberg Essential Blocks <= 6.0.4 – Authenticated (Contributor+) Stored Cross-Site Scripting via Block Attributes
The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the className, classHook, and blockId attributes in the Add to Cart block (essential-blocks/add-to-cart) in all versions up…
*-6.0.4
6.1.0
01/05/2026
Essential Blocks <= 5.7.2 – Missing Authorization To Authenticated (Author+) Information Disclosure
The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to unauthorized access of data due to a missing or incorrect capability checks on the get_instagram_access_token_callback, google_map_api_key_save_callback and get_siteinfo functions in…
*-5.7.2
5.7.3
16/12/2025
Essential Blocks <= 5.7.1 – Authenticated (Author+) Server-Side Request Forgery
The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5.7.1 via the eb_save_ai_generated_image function. This makes it possible for…
*-5.7.1
5.7.2
17/10/2025
Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns <= 5.7.1 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'titleTag' attribute in all versions up to, and including, 5.7.1 due to insufficient input sanitization…
*-5.7.1
5.7.2
17/10/2025
Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates <= 5.4.0 – Authenticated (Contributor+) Stored Cross-Site Scripting via Slider and Post Carousel Widgets
The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via HTML attributes in Slider and Post Carousel widgets in all versions up to, and including, 5.4.0 due…
*-5.4.0
5.4.1
26/05/2025
Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates <= 5.3.1 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Parallax slider in all versions up to, and including, 5.3.1 due to insufficient input sanitization and…
*-5.3.1
5.3.2
07/03/2025
Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates <= 5.2.3 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data-marker’ parameter in all versions up to, and including, 5.2.3 due to insufficient input sanitization and…
*-5.2.3
5.3.0
25/02/2025
Essential Blocks for Gutenberg <= 4.8.3 – Missing Authorization
The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 4.8.3. This makes…
*-4.8.3
4.8.4
22/02/2025
Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates <= 5.0.9 – Authenticated (Admin+) Stored Cross-Site Scripting
The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the maker title value of the Google Maps block in all versions up to, and including, 5.0.9…
*-5.1.0
5.1.1
07/01/2025
Essential Blocks for Gutenberg <= 4.8.4 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Essential Blocks for Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.8.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level…
*-4.8.4
4.9.0
30/09/2024
Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates <= 4.6.1 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'post-carousel' block in all versions up to, and including, 4.6.1 due to insufficient input sanitization and…
*-4.6.1
4.7.0
12/07/2024
Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates <= 4.5.12 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘tagName’ parameter in versions up to, and including, 4.5.12 due to insufficient input sanitization and output…
*-4.5.12
4.5.13
16/05/2024
Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates <= 4.5.9 – Authenticated (Contributor+) DOM-Based Cross-Site Scripting via "Social Icons" Block
The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's "Social Icons" block in all versions up to, and including, 4.5.9 due to insufficient input…
*-4.5.9
4.5.10
18/04/2024
Essential Blocks for Gutenberg <= 4.5.3 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Essential Blocks for Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.5.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level…
*-4.5.3
4.5.4
05/04/2024
Essential Blocks for Gutenberg <= 4.4.9 – Missing Authorization
The Essential Blocks for Gutenberg plugin for WordPress is vulnerable to unauthorized access due to a missing capability check in versions up to, and including, 4.4.9. This makes it possible for authenticated attackers, with contributor-level access and above,…
*-4.4.9
4.4.10
28/03/2024
Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates <= 4.5.3 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets in all versions up to, and including, 4.5.3 due to insufficient input sanitization and…
*-4.5.3
4.5.4
19/03/2024
Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates <= 4.5.1 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the blockId parameter in all versions up to, and including, 4.5.1 due to insufficient input sanitization and…
*-4.5.1
4.5.2
28/02/2024
Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates <= 4.4.6 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Table of Contents block in all versions up to, and including, 4.4.6 due to insufficient input…
*-4.4.6
4.4.7
09/01/2024
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.