Extension WordPress

Vulnérabilités Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns, page 2

Cette page rassemble les failles publiées pour Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns, leurs plages de versions affectées et les correctifs signalés dans la base locale.

31Vulnérabilités
1Critiques
31Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns

31 fiches

CVE-2023-51359 Moyenne · 5,4
Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns

Essential Blocks for Gutenberg <= 4.2.0 – Incorrect Authorization Checks

The Essential Blocks for Gutenberg plugin for WordPress is vulnerable to unauthorized modification of data due to improper capability checks on various functions function in versions up to, and including, 4.2.0. This makes it possible for authenticated attackers,…

Versions affectées

*-4.2.0

Correctif

4.2.1

Publication

26/12/2023

CVE-2023-6623 Critique · 9,8
Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns

Essential Blocks <= 4.4.2 – Unauthenticated Local File Inclusion

The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.4.2 via the /wp-json/essential-blocks/v1/queries REST API endpoint. This makes it possible…

Versions affectées

*-4.4.2

Correctif

4.4.3

Publication

21/12/2023

CVE-2023-47760 Moyenne · 4,3
Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns

Essential Blocks for Gutenberg <= 4.2.0 – Missing Authorization via AJAX actions

The Essential Blocks for Gutenberg plugin for WordPress is vulnerable to unauthorized access to AJAX actions due to a missing capability check on several functions in versions up to, and including, 4.2.0. This makes it possible for authenticated…

Versions affectées

*-4.2.0

Correctif

4.2.1

Publication

13/11/2023

CVE-2023-4386 Élevée · 8,1
Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns

Essential Blocks <= 4.2.0 – Unauthenticated PHP Object Injection via queries

The Essential Blocks plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.2.0 via deserialization of untrusted input in the get_posts function. This allows unauthenticated attackers to inject a PHP Object. No…

Versions affectées

*-4.2.0

Correctif

4.2.1

Publication

13/09/2023

CVE-2023-4402 Élevée · 8,1
Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns

Essential Blocks <= 4.2.0 – Unauthenticated PHP Object Injection via products

The Essential Blocks plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.2.0 via deserialization of untrusted input in the get_products function. This allows unauthenticated attackers to inject a PHP Object. No…

Versions affectées

*-4.2.0

Correctif

4.2.1

Publication

13/09/2023

CVE-2023-2083 Moyenne · 4,3
Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns

Essential Blocks <= 4.0.6 – Missing Authorization via save

The Essential Blocks plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check on the save function in versions up to, and including, 4.0.6. This makes it possible for subscriber-level attackers to…

Versions affectées

*-4.0.6

Correctif

4.0.7

Publication

18/04/2023

CVE-2023-2087 Moyenne · 4,3
Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns

Essential Blocks <= 4.0.6 – Cross-Site Request Forgery via save

The Essential Blocks plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.0.6. This is due to missing or incorrect nonce validation on the save function. This makes it possible for unauthenticated…

Versions affectées

*-4.0.6

Correctif

4.0.7

Publication

18/04/2023

CVE-2023-2085 Moyenne · 4,3
Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns

Essential Blocks <= 4.0.6 – Missing Authorization via templates

The Essential Blocks plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check on the templates function in versions up to, and including, 4.0.6. This makes it possible for subscriber-level attackers to…

Versions affectées

*-4.0.6

Correctif

4.0.7

Publication

18/04/2023

CVE-2023-2086 Moyenne · 4,3
Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns

Essential Blocks <= 4.0.6 – Missing Authorization via template_count

The Essential Blocks plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check on the template_count function in versions up to, and including, 4.0.6. This makes it possible for subscriber-level attackers to…

Versions affectées

*-4.0.6

Correctif

4.0.7

Publication

18/04/2023

CVE-2023-2084 Moyenne · 4,3
Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns

Essential Blocks <= 4.0.6 – Missing Authorization via get

The Essential Blocks plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check on the get function in versions up to, and including, 4.0.6. This makes it possible for subscriber-level attackers to…

Versions affectées

*-4.0.6

Correctif

4.0.7

Publication

18/04/2023

CVE-2022-47594 Moyenne · 4,3
Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns

Essential Blocks for Gutenberg <= 3.8.5 – Cross-Site Request Forgery

The Essential Blocks for Gutenberg plugin for WordPress is vulnerable to authorization bypass due to incorrectly defined capability checks throughout the 'EB_Openverse_Ajax' class in versions up to, and including, 3.8.5. This makes it possible for unauthenticated attackers to…

Versions affectées

*-3.8.5

Correctif

3.8.6

Publication

20/01/2023

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités