Extension WordPress

Vulnérabilités Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE

Cette page rassemble les failles publiées pour Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE, leurs plages de versions affectées et les correctifs signalés dans la base locale.

13Vulnérabilités
0Critiques
13Avec correctif
8,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE

13 fiches

CVE-2026-2892 Élevée · 7,5
Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE

Otter Blocks <= 3.1.4 – Improper Authorization to Unauthenticated Purchase Verification Bypass via Forged Cookie

The Otter Blocks plugin for WordPress is vulnerable to Purchase Verification Bypass in all versions up to, and including, 3.1.4. This is due to the 'get_customer_data' method relying on an unsigned 'o_stripe_data' cookie to determine Stripe product ownership…

Versions affectées

*-3.1.4

Correctif

3.1.5

Publication

29/04/2026

CVE-2025-55715 Moyenne · 5,3
Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE

Otter – Gutenberg Block <= 3.1.0 – Unauthenticated Sensitive Information Exposure

The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.1.0. This makes it possible for unauthenticated attackers to…

Versions affectées

*-3.1.0

Correctif

3.1.1

Publication

27/08/2025

CVE-2024-11219 Moyenne · 5,3
Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE

Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE <= 3.0.6 – Unauthetnicated Path Traversal to Arbitrary Image View

The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 3.0.6 via the get_image function. This makes it possible for…

Versions affectées

*-3.0.6

Correctif

3.0.7

Publication

26/11/2024

CVE-2024-10367 Moyenne · 6,4
Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE

Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE <= 3.0.4 – Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload

The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API SVG File uploads in all versions up to, and including, 3.0.4 due to…

Versions affectées

*-3.0.4

Correctif

3.0.5

Publication

31/10/2024

CVE-2024-3725 Moyenne · 6,4
Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE

Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE <= 2.6.9 – Authenticated (Contributor+) Stored Cross-Site Scripting via 'titleTag'

The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Post Grid widget in all versions up to, and including, 2.6.9 due to…

Versions affectées

*-2.6.9

Correctif

2.6.10

Publication

16/04/2024

CVE-2024-3344 Moyenne · 6,4
Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE

Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE <= 2.6.8 – Authenticated (Author+) Limited File Upload to Stored Cross-Site Scripting

The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG file upload in all versions up to, and including, 2.6.8 due to insufficient input…

Versions affectées

*-2.6.8

Correctif

2.6.9

Publication

10/04/2024

CVE-2024-3343 Moyenne · 6,4
Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE

Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE <= 2.6.8 – Authenticated (Contributor+) Stored Cross-Site Scripting via Block Attributes

The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's block attributes in all versions up to, and including, 2.6.8 due to insufficient…

Versions affectées

*-2.6.8

Correctif

2.6.9

Publication

10/04/2024

CVE-2024-2729 Moyenne · 6,4
Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE

Otter Blocks <= 2.6.5 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via new post creation in all versions up to, and including, 2.6.5 due to insufficient input…

Versions affectées

*-2.6.5

Correctif

2.6.6

Publication

28/03/2024

CVE-2024-2841 Moyenne · 6,4
Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE

Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE <= 2.6.5 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets in all versions up to, and including, 2.6.5 due to insufficient input…

Versions affectées

*-2.6.5

Correctif

2.6.6

Publication

28/03/2024

CVE-2024-2226 Moyenne · 6,4
Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE

Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE <= 2.6.4 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the id parameter in the google-map block in all versions up to, and including, 2.6.4…

Versions affectées

*-2.6.4

Correctif

2.6.5

Publication

13/03/2024

CVE-2024-1047 Moyenne · 5,3
Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE

ThemeIsle SDK <= Various Versions – Missing Authorization

Multiple plugins and/or themes for WordPress with the ThemeIsle SDK are vulnerable to unauthorized modification of data due to a missing capability check on the register_reference() function in various versions. This makes it possible for unauthenticated attackers to…

Versions affectées

*-2.6.2

Correctif

2.6.3

Publication

01/02/2024

CVE-2023-2288 Élevée · 8,8
Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE

Otter – Gutenberg Blocks <= 2.2.5 – Authenticated (Author+) PHAR Deserialization

The Otter – Gutenberg Blocks plugin for WordPress is vulnerable to deserialization of untrusted input via the 'fallback' parameter in versions up to, and including 1.2.7. This makes it possible for authenticated attackers with author privileges to call…

Versions affectées

*-2.2.5

Correctif

2.2.6

Publication

02/05/2023

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités