Extension WordPress
Vulnérabilités Custom Block Builder – Lazy Blocks
Cette page rassemble les failles publiées pour Custom Block Builder – Lazy Blocks, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Custom Block Builder – Lazy Blocks
4 fiches
Custom Block Builder – Lazy Blocks < 4.3.0 – Authenticated (Administrator+) Stored Cross-Site Scripting
The Custom Block Builder – Lazy Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 4.3.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level…
[*, 4.3.0)
4.3.0
11/06/2026
Custom Block Builder – Lazy Blocks <= 4.2.0 – Authenticated (Contributor+) Remote Code Execution
The Custom Block Builder – Lazy Blocks plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.2.0 via multiple functions in the 'LazyBlocks_Blocks' class. This makes it possible for authenticated attackers,…
*-4.2.0
4.2.1
10/02/2026
Lazy Blocks <= 4.1.0 – Missing Authorization
The Lazy Blocks plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the maybe_export_json() function in versions up to, and including, 4.1.0. This makes it possible for authenticated attackers, with…
*-4.1.0
4.1.1
22/09/2025
Custom Block Builder – Lazy Blocks <= 3.8.2 – Reflected Cross-Site Scripting
The Custom Block Builder – Lazy Blocks plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 3.8.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…
*-3.8.2
3.8.3
04/02/2025
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.