Extension WordPress
Vulnérabilités Responsive Blocks – Page Builder for Blocks & Patterns
Cette page rassemble les failles publiées pour Responsive Blocks – Page Builder for Blocks & Patterns, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Responsive Blocks – Page Builder for Blocks & Patterns
10 fiches
Responsive Blocks <= 2.2.1 – Missing Authorization to Authenticated (Contributor+) Arbitrary Modification via AJAX Actions
The Responsive Blocks – Page Builder for Blocks & Patterns plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 2.2.1. This is due to the plugin not properly verifying that a user…
2.0.9-2.2.1
2.2.2
20/04/2026
Responsive Blocks <= 2.2.0 – Unauthenticated Open Email Relay via REST API 'email_to' Parameter
The Responsive Blocks – Page Builder for Blocks & Patterns plugin for WordPress is vulnerable to Unauthenticated Open Email Relay in all versions up to, and including, 2.2.0. This is due to insufficient authorization checks and missing server-side…
*-2.2.0
2.2.1
20/04/2026
Responsive Blocks – Page Builder for Blocks & Patterns <= 2.2.0 – Missing Authorization
The Responsive Blocks – Page Builder for Blocks & Patterns plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.2.0. This makes it…
*-2.2.0
2.2.1
11/03/2026
Responsive Blocks <= 2.0.6 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Responsive Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.0.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and…
*-2.0.6
2.0.7
27/06/2025
Responsive Blocks <= 2.0.5 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Responsive Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.0.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and…
*-2.0.5
2.0.6
12/06/2025
Responsive Blocks <= 2.0.2 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Responsive Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and…
*-2.0.2
2.0.3
16/04/2025
Responsive Blocks <= 1.9.9 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Responsive Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.9.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and…
*-1.9.9
2.0.0
31/01/2025
Responsive Blocks – WordPress Gutenberg Blocks <= 1.9.9 – Authenticated (Contributor+) Stored Cross-Site Scripting via section_tag Parameter
The Responsive Blocks – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘section_tag’ parameter in all versions up to, and including, 1.9.9 due to insufficient input sanitization and output escaping. This makes…
*-1.9.9
2.0.0
29/01/2025
Responsive Blocks – WordPress Gutenberg Blocks <= 1.9.7 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Responsive Blocks – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'responsive-block-editor-addons/portfolio' block in all versions up to, and including, 1.9.7 due to insufficient input sanitization and output escaping. This makes…
*-1.9.7
1.9.8
23/12/2024
Responsive Blocks – WordPress Gutenberg Blocks <= 1.8.8 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Responsive Blocks – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the taxonomy block in versions up to, and including, 1.8.8 due to insufficient input sanitization and output escaping. This makes it…
*-1.8.8
1.8.9
16/08/2024
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.