Extension WordPress
Vulnérabilités Vayu Blocks – Website Builder for the Gutenberg Block Editor
Cette page rassemble les failles publiées pour Vayu Blocks – Website Builder for the Gutenberg Block Editor, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Vayu Blocks – Website Builder for the Gutenberg Block Editor
5 fiches
Vayu Blocks <= 1.3.9 – Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Block Attributes
The Vayu Blocks – Website Builder for the Block Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple attributes in the Lottie block in all versions up to, and including, 1.3.9 due to insufficient input…
*-1.3.9
1.3.10
02/09/2025
Vayu Blocks <= 1.3.1 – Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting via containerWidth Parameter
The Vayu Blocks – Gutenberg Blocks for WordPress & WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘containerWidth’ parameter in all versions up to, and including, 1.3.1 due to a missing capability check on…
*-1.3.1
1.3.2
02/06/2025
Vayu Blocks – Gutenberg Blocks for WordPress & WooCommerce 1.0.4 – 1.2.1 – Missing Authorization to Unauthenticated Limited Arbitrary Options Update
The Vayu Blocks – Gutenberg Blocks for WordPress & WooCommerce plugin for WordPress is vulnerable to unauthorized access and modification of data due to missing capability checks on the 'vayu_blocks_get_toggle_switch_values_callback' and 'vayu_blocks_save_toggle_switch_callback' function in versions 1.0.4 to 1.2.1.…
1.0.4-1.2.1
1.2.2
07/04/2025
Vayu Blocks – Gutenberg Blocks for WordPress & WooCommerce <= 1.3.7 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Vayu Blocks – Gutenberg Blocks for WordPress & WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3.7 due to insufficient input sanitization and output escaping. This makes it possible…
*-1.3.7
Non indiqué
03/02/2025
Vayu Blocks – Gutenberg Blocks for WordPress & WooCommerce <= 1.1.1 – Missing Authorization to Unauthenticated Arbitrary Plugin Installation/Activation
The Vayu Blocks – Gutenberg Blocks for WordPress & WooCommerce plugin for WordPress is vulnerable to unauthorized arbitrary plugin installation and activation due to a missing capability check on the tp_install() function in all versions up to, and…
*-1.1.1
1.2.0
11/12/2024
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.