aBlocks – Gutenberg Blocks, User Dashboard Builder, Popup Builder, Form Builder & Animation Builder < 2.9.1 - Authenticated (Contributor+) Privilege Escalation
high
The aBlocks – Gutenberg Blocks, User Dashboard Builder, Popup Builder, Form Builder & Animation Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to 2.9.1 (exclusive). This makes it possible for authenticated attackers, with Contributor-level access and above, to elevate their privil...
- CVSS:
- 8.8
- Affected:
- up to 2.9.1
- Fixed in:
- 2.9.1
- Disclosed:
- Jul 7, 2026
CVE-2026-57386 on NVD →
aBlocks – WordPress Gutenberg Blocks <= 2.4.0 - Missing Authorization to Authenticated (Subscriber+) Settings Modification
medium
The aBlocks – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized modification of data and disclosure of sensitive information due to missing capability checks on multiple AJAX actions in all versions up to, and including, 2.4.0. This makes it possible for authenticated attackers, with subscri...
- CVSS:
- 5.4
- Affected:
- up to 2.4.0
- Fix:
- No patched version reported
- Disclosed:
- Jan 6, 2026
CVE-2025-12449 on NVD →
aBlocks <= 1.9.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The aBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.9.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that wil...
- CVSS:
- 6.4
- Affected:
- up to 1.9.2
- Fixed in:
- 1.9.3
- Disclosed:
- May 7, 2025
CVE-2025-47616 on NVD →
aBlocks – WordPress Gutenberg Blocks <= 1.6.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The aBlocks – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the "Table Of Content" Block, specifically in the "markerView" attribute, in all versions up to, and including, 1.6.1 due to insufficient input sanitization and output escaping. This makes it possible for auth...
- CVSS:
- 6.4
- Affected:
- up to 1.6.1
- Fixed in:
- 1.6.2
- Disclosed:
- Feb 17, 2025
CVE-2024-13465 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database