Extension WordPress

Vulnérabilités Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid

Cette page rassemble les failles publiées pour Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid, leurs plages de versions affectées et les correctifs signalés dans la base locale.

6Vulnérabilités
0Critiques
6Avec correctif
6,4CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid

6 fiches

CVE-2026-57650 Moyenne · 6,4
Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid

Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid <= 1.8.3 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.8.3 due to insufficient input…

Versions affectées

*-1.8.3

Correctif

1.8.4

Publication

26/06/2026

CVE-2026-40728 Moyenne · 4,3
Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid

Magazine Blocks <= 1.8.3 – Missing Authorization

The Magazine Blocks plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.8.3. This makes it possible for authenticated attackers, with contributor-level access and…

Versions affectées

*-1.8.3

Correctif

1.8.4

Publication

26/02/2026

CVE-2024-56258 Moyenne · 6,4
Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid

Magazine Blocks <= 1.3.20 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Magazine Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3.20 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and…

Versions affectées

*-1.3.20

Correctif

1.3.21

Publication

30/12/2024

CVE-2024-50429 Moyenne · 6,4
Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid

Magazine Blocks <= 1.3.15 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Magazine Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3.15 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and…

Versions affectées

*-1.3.15

Correctif

1.3.18

Publication

24/10/2024

CVE-2024-9218 Moyenne · 6,1
Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid

Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid <= 1.3.14 – Reflected Cross-Site Scripting

The Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the…

Versions affectées

*-1.3.14

Correctif

1.3.15

Publication

01/10/2024

CVE-2024-34760 Moyenne · 6,4
Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid

Magazine Blocks <= 1.3.6 – Authenticated (Author+) Stored Cross-Site Scripting

The Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post title markup parameter in all versions up to,…

Versions affectées

*-1.3.6

Correctif

1.3.7

Publication

14/05/2024

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités