Extension WordPress

Vulnérabilités Getwid – Gutenberg Blocks

Cette page rassemble les failles publiées pour Getwid – Gutenberg Blocks, leurs plages de versions affectées et les correctifs signalés dans la base locale.

12Vulnérabilités
0Critiques
12Avec correctif
8,5CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Getwid – Gutenberg Blocks

12 fiches

CVE-2025-58252 Moyenne · 4,3
Getwid – Gutenberg Blocks

Getwid <= 2.1.2 – Authenticated (Contributor+) Sensitive Information Exposure

The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1.2. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive user…

Versions affectées

*-2.1.2

Correctif

2.1.3

Publication

22/09/2025

CVE-2024-5020 Moyenne · 6,4
Getwid – Gutenberg Blocks

Multiple Plugins <= (Various Versions) – Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via FancyBox JavaScript Library

Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled FancyBox JavaScript library (versions 1.3.4 to 3.5.7) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes…

Versions affectées

*-2.0.11

Correctif

2.0.12

Publication

03/12/2024

CVE-2024-10872 Moyenne · 6,4
Getwid – Gutenberg Blocks

Getwid – Gutenberg Blocks <= 2.0.12 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `template-post-custom-field` block in all versions up to, and including, 2.0.12 due to insufficient input sanitization and output escaping. This makes it possible…

Versions affectées

*-2.0.12

Correctif

2.0.13

Publication

19/11/2024

CVE-2024-6491 Moyenne · 4,3
Getwid – Gutenberg Blocks

Getwid – Gutenberg Blocks <= 2.0.10 – Missing Authentication to MailChimp API key update

The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the mailchimp_api_key_manage function in all versions up to, and including, 2.0.10. This makes it possible for…

Versions affectées

*-2.0.10

Correctif

2.0.11

Publication

19/07/2024

CVE-2024-3588 Moyenne · 6,4
Getwid – Gutenberg Blocks

Getwid – Gutenberg Blocks <= 2.0.7 – Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via 'Countdown'

The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Countdown block in all versions up to, and including, 2.0.7 due to insufficient input sanitization and output escaping on user supplied…

Versions affectées

*-2.0.7

Correctif

2.0.8

Publication

26/04/2024

CVE-2024-1948 Moyenne · 6,4
Getwid – Gutenberg Blocks

Getwid – Gutenberg Blocks <= 2.0.5 – Authenticated(Contributor+) Stored Cross-Site Scripting via Block Content

The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the block content in all versions up to, and including, 2.0.5 due to insufficient input sanitization and output escaping. This makes it possible…

Versions affectées

*-2.0.5

Correctif

2.0.6

Publication

21/03/2024

CVE-2023-6959 Moyenne · 4,3
Getwid – Gutenberg Blocks

Getwid – Gutenberg Blocks <= 2.0.4 – Missing Authorization to Recaptcha API Key Modification

The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the recaptcha_api_key_manage function in all versions up to, and including, 2.0.3. This makes it possible for…

Versions affectées

*-2.0.4

Correctif

2.0.5

Publication

17/01/2024

CVE-2023-1895 Élevée · 8,5
Getwid – Gutenberg Blocks

Getwid – Gutenberg Blocks <= 1.8.3 – Authenticated(Subscriber+) Server Side Request Forgery

The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to Server Side Request Forgery via the get_remote_content REST API endpoint in versions up to, and including, 1.8.3. This can allow authenticated attackers with subscriber-level permissions or above…

Versions affectées

*-1.8.3

Correctif

1.8.4

Publication

06/06/2023

CVE-2023-1910 Moyenne · 4,3
Getwid – Gutenberg Blocks

Getwid – Gutenberg Blocks <= 1.8.3 – Improper Authorization via get_remote_templates REST endpoint

The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized modification of data due to an insufficient capability check on the get_remote_templates function in versions up to, and including, 1.8.3. This makes it possible for authenticated…

Versions affectées

*-1.8.3

Correctif

1.8.4

Publication

06/06/2023

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités