Extension WordPress
Vulnérabilités Spectra Legacy – Gutenberg Blocks
Cette page rassemble les failles publiées pour Spectra Legacy – Gutenberg Blocks, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Spectra Legacy – Gutenberg Blocks
29 fiches
Spectra Gutenberg Blocks <= 2.19.28 – Authenticated (Contributor+) Stored Cross-Site Scripting via uagb/image Block
The Spectra Gutenberg Blocks – Website Builder for the Block Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `uagb/image` block in all versions up to, and including, 2.19.28 due to insufficient input sanitization and…
*-2.19.28
2.19.29
20/07/2026
Spectra Gutenberg Blocks <= 2.19.25 – Authenticated (Contributor+) Remote Code Execution via Arbitrary PHP Function Call via Block Attributes
The Spectra Gutenberg Blocks – Website Builder for the Block Editor plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.19.25. This makes it possible for authenticated attackers, with Contributor-level access…
*-2.19.25
2.19.26
29/05/2026
Spectra <= 2.19.22 – Missing Authorization
The Spectra plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.19.22. This makes it possible for authenticated attackers, with contributor-level access and above,…
*-2.19.22
2.19.23
27/03/2026
Spectra Gutenberg Blocks <= 2.19.17 – Unauthenticated Information Disclosure in Sensitive Data
The Spectra Gutenberg Blocks – Website Builder for the Block Editor plugin for WordPress is vulnerable to Information Disclosure in all versions up to, and including, 2.19.17. This is due to the plugin failing to check `post_password_required()` before…
*-2.19.17
2.19.18
02/02/2026
Spectra <= 2.19.17 – Missing Authorization
The Spectra Gutenberg Blocks – Website Builder for the Block Editor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.19.17. This makes…
*-2.19.17
2.19.18
17/01/2026
Spectra <= 2.19.14 – Authenticated (Contributor+) Stored Cross-Site Scripting via Custom CSS
The Spectra Gutenberg Blocks – Website Builder for the Block Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custom CSS in all versions up to, and including, 2.19.14 due to insufficient input sanitization and…
*-2.19.14
2.19.15
04/11/2025
Spectra – WordPress Gutenberg Blocks <= 2.19.0 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the uagb block in all versions up to, and including, 2.19.0 due to insufficient input sanitization and output escaping. This makes it…
*-2.19.0
2.19.1
25/03/2025
Spectra – WordPress Gutenberg Blocks <= 2.16.2 – Authenticated (Contributor+) Stored Cross-Site Scripting via Team Widget
The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'Team' widget in all versions up to, and including, 2.16.2 due to insufficient input sanitization and output escaping on user…
*-2.16.2
2.16.3
02/12/2024
Spectra – WordPress Gutenberg Blocks <= 2.15.0 – Authenticated (Contributor+) Stored Cross-site Scripting
The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the FAQ heading tag in all versions up to, and including, 2.15.0 due to insufficient input sanitization and output escaping on user…
*-2.15.0
2.15.1
07/08/2024
Spectra <= 2.13.7 – Missing Authorization via generate_ai_content
The Spectra plugin for WordPress is vulnerable to unauthorized modification of data due to an insufficient capability check on the generate_ai_content() function in versions up to, and including, 2.13.7. This makes it possible for authenticated attackers, with contributor-level…
*-2.13.7
2.13.8
05/07/2024
Spectra – WordPress Gutenberg Blocks <= 2.13.0 – Authenticated (Author+) Stored Cross-Site Scripting
The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘block_id’ parameter in versions up to, and including, 2.13.0 due to insufficient input sanitization and output escaping. This makes it possible…
*-2.13.0
2.13.1
23/05/2024
Spectra – WordPress Gutenberg Blocks <= 2.12.8 – Authenticated (Contributor+) Stored Cross-Site Scripting via Testimonial Block
The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Testimonial block in all versions up to, and including, 2.12.8 due to insufficient input sanitization and output escaping on user…
*-2.12.8
2.12.9
22/05/2024
Spectra – WordPress Gutenberg Blocks <= 2.12.8 – Authenticated (Contributor+) Stored Cross-Site Scripting via Image Gallery Block
The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Gallery block in all versions up to, and including, 2.12.8 due to insufficient input sanitization and output escaping on…
*-2.12.8
2.12.9
22/05/2024
Spectra – WordPress Gutenberg Blocks <= 2.12.6 – Authenticated (Contributor+) Path Traversal
The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Path Traversal in versions up to, and including, 2.12.6 via the get_block_default_attributes function. This allows authenticated attackers, with contributor-level permissions and above, to read the contents…
*-2.12.6
2.12.7
26/04/2024
Spectra – WordPress Gutenberg Blocks <= 2.10.3 – Authenticated(Contributor+) Cross-Site Scripting via Custom CSS
The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custom CSS metabox in all versions up to and including 2.10.3 due to insufficient input sanitization and output escaping. This makes…
*-2.10.3
2.10.4
03/04/2024
Spectra <= 2.7.9 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Spectra plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.7.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above,…
*-2.7.9
2.7.10
05/12/2023
Spectra <= 2.6.6 – Missing Authorization
The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.6.6. This makes it possible for authenticated attackers,…
*-2.6.6
2.6.7
14/07/2023
Spectra <= 2.6.6 – Authenticated (Contributor+) Server-Side Request Forgery in template_importer
The Spectra plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 2.6.6 via the template_importer function. This can allow authenticated attackers, with contributor-level permissions and above, to make web requests to arbitrary…
*-2.6.6
2.6.7
14/07/2023
Spectra <= 2.6.6 – Authenticated (Contributor+) Server-Side Request Forgery in import_wpforms
The Spectra plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 2.6.6 via the import_wpforms function. This can allow authenticated attackers, with contributor-level permissions and above, to make web requests to arbitrary…
*-2.6.6
2.6.7
14/07/2023
Spectra – WordPress Gutenberg Blocks <= 2.3.1 – Missing Authorization Checks
The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the import_wpforms, import_block, and activate_plugin functions called via AJAX actions in versions up to, and including, 2.3.1.…
*-2.3.1
2.3.2
25/01/2023
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.