Thème WordPress

Vulnérabilités Blocksy

Cette page rassemble les failles publiées pour Blocksy, leurs plages de versions affectées et les correctifs signalés dans la base locale.

14Vulnérabilités
0Critiques
14Avec correctif
8,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Blocksy

14 fiches

CVE-2026-8365 Élevée · 8,8
Blocksy

Blocksy <= 2.1.41 – Authenticated (Contributor+) PHP Object Injection via Deserialization of Untrusted Data via 'blocksy_meta' REST API Field

The Blocksy theme for WordPress is vulnerable to PHP Object Injection leading to Remote Code Execution via the 'blocksy_meta' REST API field and the V200 database migration in versions up to and including 2.1.35. This is due to…

Versions affectées

*-2.1.41

Correctif

2.1.42

Publication

08/06/2026

CVE-2026-2583 Moyenne · 6,4
Blocksy

Blocksy <= 2.1.30 – Authenticated (Contributor+) Stored Cross-Site Scripting via `blocksy_meta` Fields

The Blocksy theme for WordPress is vulnerable to Stored Cross-Site Scripting via the `blocksy_meta` metadata fields in all versions up to, and including, 2.1.30 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…

Versions affectées

*-2.1.30

Correctif

2.1.31

Publication

02/03/2026

CVE-2025-47465 Faible · 2,7
Blocksy

Blocksy <= 2.0.97 – Missing Authorization

The Blocksy theme for WordPress is vulnerable to unauthorized access due to a missing capability check on the wp_ajax_blocksy_notice_button_click AJAX endpoint in versions up to, and including, 2.0.97. This makes it possible for authenticated attackers, with administrator-level access…

Versions affectées

*-2.0.97

Correctif

2.0.98

Publication

07/05/2025

CVE-2024-37469 Moyenne · 4,3
Blocksy

Blocksy <= 2.0.22 – Cross-Site Request Forgery

The Blocksy theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.22. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to…

Versions affectées

*-2.0.22

Correctif

2.0.23

Publication

01/07/2024

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités