Extension WordPress
Vulnérabilités ZoloBlocks – Advanced Gutenberg Blocks, Website Builder & Page Design Toolkit
Cette page rassemble les failles publiées pour ZoloBlocks – Advanced Gutenberg Blocks, Website Builder & Page Design Toolkit, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de ZoloBlocks – Advanced Gutenberg Blocks, Website Builder & Page Design Toolkit
6 fiches
ZoloBlocks <= 2.3.11 – Missing Authorization
The ZoloBlocks – Gutenberg Block Editor Plugin with Advanced Blocks, Dynamic Content, Templates & Patterns plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and…
*-2.3.11
2.3.12
04/11/2025
ZoloBlocks <= 2.3.11 – Missing Authorization to Unauthenticated Popup Enable/Disable
The ZoloBlocks – Gutenberg Block Editor Plugin with Advanced Blocks, Dynamic Content, Templates & Patterns plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the update_popup_status() function in all versions…
*-2.3.11
2.3.12
23/10/2025
ZoloBlocks – Gutenberg Block Editor Plugin with Advanced Blocks, Dynamic Content, Templates & Patterns <= 2.3.10 – Authenticated (Contributor+) Stored Cross-Site Scripting
The ZoloBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple Gutenberg blocks in versions up to, and including, 2.3.10. This is due to insufficient input sanitization and output escaping on user-supplied attributes within multiple block…
*-2.3.10
2.3.11
30/09/2025
ZoloBlocks <= 2.3.11 – Unauthenticated Sever-Side Request Forgery
The ZoloBlocks – Gutenberg Block Editor Plugin with Advanced Blocks, Dynamic Content, Templates & Patterns plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.3.11. This makes it possible for unauthenticated…
*-2.3.11
2.3.12
26/09/2025
ZoloBlocks <= 2.3.12 – Authenticated (Contributor+) Stored Cross-Site Scripting
The ZoloBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.3.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above,…
*-2.3.12
2.3.13
22/09/2025
ZoloBlocks <= 2.3.2 – Authenticated (Subscriber+) Local File Inclusion
The ZoloBlocks plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.3.2. This makes it possible for authenticated attackers, with subscriber-level access and above, to include and execute arbitrary files on the…
*-2.3.2
2.3.3
07/08/2025
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.