Extension WordPress

Vulnérabilités Vayu Blocks – Website Builder for the Gutenberg Block Editor

Cette page rassemble les failles publiées pour Vayu Blocks – Website Builder for the Gutenberg Block Editor, leurs plages de versions affectées et les correctifs signalés dans la base locale.

5Vulnérabilités
1Critiques
4Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Vayu Blocks – Website Builder for the Gutenberg Block Editor

5 fiches

CVE-2025-9378 Moyenne · 6,4
Vayu Blocks – Website Builder for the Gutenberg Block Editor

Vayu Blocks <= 1.3.9 – Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Block Attributes

The Vayu Blocks – Website Builder for the Block Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple attributes in the Lottie block in all versions up to, and including, 1.3.9 due to insufficient input…

Versions affectées

*-1.3.9

Correctif

1.3.10

Publication

02/09/2025

CVE-2025-4420 Moyenne · 6,4
Vayu Blocks – Website Builder for the Gutenberg Block Editor

Vayu Blocks <= 1.3.1 – Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting via containerWidth Parameter

The Vayu Blocks – Gutenberg Blocks for WordPress & WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘containerWidth’ parameter in all versions up to, and including, 1.3.1 due to a missing capability check on…

Versions affectées

*-1.3.1

Correctif

1.3.2

Publication

02/06/2025

CVE-2025-2568 Moyenne · 5,3
Vayu Blocks – Website Builder for the Gutenberg Block Editor

Vayu Blocks – Gutenberg Blocks for WordPress & WooCommerce 1.0.4 – 1.2.1 – Missing Authorization to Unauthenticated Limited Arbitrary Options Update

The Vayu Blocks – Gutenberg Blocks for WordPress & WooCommerce plugin for WordPress is vulnerable to unauthorized access and modification of data due to missing capability checks on the 'vayu_blocks_get_toggle_switch_values_callback' and 'vayu_blocks_save_toggle_switch_callback' function in versions 1.0.4 to 1.2.1.…

Versions affectées

1.0.4-1.2.1

Correctif

1.2.2

Publication

07/04/2025

CVE-2025-22644 Moyenne · 6,4
Vayu Blocks – Website Builder for the Gutenberg Block Editor

Vayu Blocks – Gutenberg Blocks for WordPress & WooCommerce <= 1.3.7 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Vayu Blocks – Gutenberg Blocks for WordPress & WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3.7 due to insufficient input sanitization and output escaping. This makes it possible…

Versions affectées

*-1.3.7

Correctif

Non indiqué

Publication

03/02/2025

CVE-2024-10124 Critique · 9,8
Vayu Blocks – Website Builder for the Gutenberg Block Editor

Vayu Blocks – Gutenberg Blocks for WordPress & WooCommerce <= 1.1.1 – Missing Authorization to Unauthenticated Arbitrary Plugin Installation/Activation

The Vayu Blocks – Gutenberg Blocks for WordPress & WooCommerce plugin for WordPress is vulnerable to unauthorized arbitrary plugin installation and activation due to a missing capability check on the tp_install() function in all versions up to, and…

Versions affectées

*-1.1.1

Correctif

1.2.0

Publication

11/12/2024

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités