Extension WordPress
Vulnérabilités Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns, page 2
Cette page rassemble les failles publiées pour Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns
31 fiches
Essential Blocks for Gutenberg <= 4.2.0 – Incorrect Authorization Checks
The Essential Blocks for Gutenberg plugin for WordPress is vulnerable to unauthorized modification of data due to improper capability checks on various functions function in versions up to, and including, 4.2.0. This makes it possible for authenticated attackers,…
*-4.2.0
4.2.1
26/12/2023
Essential Blocks <= 4.4.2 – Unauthenticated Local File Inclusion
The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.4.2 via the /wp-json/essential-blocks/v1/queries REST API endpoint. This makes it possible…
*-4.4.2
4.4.3
21/12/2023
Essential Blocks for Gutenberg <= 4.2.0 – Missing Authorization via AJAX actions
The Essential Blocks for Gutenberg plugin for WordPress is vulnerable to unauthorized access to AJAX actions due to a missing capability check on several functions in versions up to, and including, 4.2.0. This makes it possible for authenticated…
*-4.2.0
4.2.1
13/11/2023
Essential Blocks <= 4.2.0 – Unauthenticated PHP Object Injection via queries
The Essential Blocks plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.2.0 via deserialization of untrusted input in the get_posts function. This allows unauthenticated attackers to inject a PHP Object. No…
*-4.2.0
4.2.1
13/09/2023
Essential Blocks <= 4.2.0 – Unauthenticated PHP Object Injection via products
The Essential Blocks plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.2.0 via deserialization of untrusted input in the get_products function. This allows unauthenticated attackers to inject a PHP Object. No…
*-4.2.0
4.2.1
13/09/2023
Essential Blocks <= 4.0.6 – Missing Authorization via save
The Essential Blocks plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check on the save function in versions up to, and including, 4.0.6. This makes it possible for subscriber-level attackers to…
*-4.0.6
4.0.7
18/04/2023
Essential Blocks <= 4.0.6 – Cross-Site Request Forgery via save
The Essential Blocks plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.0.6. This is due to missing or incorrect nonce validation on the save function. This makes it possible for unauthenticated…
*-4.0.6
4.0.7
18/04/2023
Essential Blocks <= 4.0.6 – Missing Authorization via templates
The Essential Blocks plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check on the templates function in versions up to, and including, 4.0.6. This makes it possible for subscriber-level attackers to…
*-4.0.6
4.0.7
18/04/2023
Essential Blocks <= 4.0.6 – Missing Authorization via template_count
The Essential Blocks plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check on the template_count function in versions up to, and including, 4.0.6. This makes it possible for subscriber-level attackers to…
*-4.0.6
4.0.7
18/04/2023
Essential Blocks <= 4.0.6 – Missing Authorization via get
The Essential Blocks plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check on the get function in versions up to, and including, 4.0.6. This makes it possible for subscriber-level attackers to…
*-4.0.6
4.0.7
18/04/2023
Essential Blocks for Gutenberg <= 3.8.5 – Cross-Site Request Forgery
The Essential Blocks for Gutenberg plugin for WordPress is vulnerable to authorization bypass due to incorrectly defined capability checks throughout the 'EB_Openverse_Ajax' class in versions up to, and including, 3.8.5. This makes it possible for unauthenticated attackers to…
*-3.8.5
3.8.6
20/01/2023
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.