Cozy Blocks <= 2.2.16 - Authenticated (Contributor+) Stored Cross-Site Scripting via cozyHoverEffect Block Attribute
medium
The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 700+ Patterns, 58 Blocks & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via cozyHoverEffect Block Attribute in all versions up to, and including, 2.2.16 due to insufficient input sanitization and output escaping. This makes it...
- CVSS:
- 6.4
- Affected:
- up to 2.2.16
- Fixed in:
- 2.2.17
- Disclosed:
- Aug 24, 2026
CVE-2026-75019 on NVD →
Cozy Blocks <= 2.2.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'layoutCircle.alignment' Block Attribute
medium
The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'layoutCircle.alignment' Block Attribute in all versions up to, and including, 2.2.11 due to insufficient input sanitization and output escaping. This...
- CVSS:
- 6.4
- Affected:
- up to 2.2.11
- Fixed in:
- 2.2.12
- Disclosed:
- Jul 31, 2026
CVE-2026-15950 on NVD →
Cozy Blocks <= 2.2.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'postMeta.font.size' Block Attribute
medium
The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'postMeta.font.size' Block Attribute in all versions up to, and including, 2.2.11 due to insufficient input sanitization and output escaping. This mak...
- CVSS:
- 6.4
- Affected:
- up to 2.2.11
- Fixed in:
- 2.2.12
- Disclosed:
- Jul 28, 2026
CVE-2026-15393 on NVD →
Cozy Blocks <= 2.2.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'icon.view' Block Attribute
medium
The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'icon.view' Block Attribute in all versions up to, and including, 2.2.11 due to insufficient input sanitization and output escaping. This makes it pos...
- CVSS:
- 6.4
- Affected:
- up to 2.2.11
- Fixed in:
- 2.2.12
- Disclosed:
- Jul 23, 2026
CVE-2026-15334 on NVD →
Cozy Blocks <= 2.2.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'cozyCustomFont' Block Attribute
medium
The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'cozyCustomFont' Block Attribute in all versions up to, and including, 2.2.11 due to insufficient input sanitization and output escaping. This makes i...
- CVSS:
- 6.4
- Affected:
- up to 2.2.11
- Fixed in:
- 2.2.12
- Disclosed:
- Jul 23, 2026
CVE-2026-15333 on NVD →
Cozy Blocks <= 2.1.29 - Unauthenticated Arbitrary Shortcode Execution
medium
The The Cozy Blocks – All-in-One Page Builder Blocks for Gutenberg and Full Site Editing (FSE) plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.1.29. This is due to the software allowing users to execute an action that does not properly validate a value before...
- CVSS:
- 6.5
- Affected:
- up to 2.1.29
- Fixed in:
- 2.1.30
- Disclosed:
- Sep 22, 2025
CVE-2025-59573 on NVD →
Cozy Blocks <= 2.1.22 - Missing Authorization
medium
The Cozy Blocks – Page Builder for Gutenberg & Site Editor with Post Blocks, WooCommerce Blocks, Magazine Blocks & WordPress Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several REST API endpoints in all versions up to, and including, 2.1.22. This makes...
- CVSS:
- 5.3
- Affected:
- up to 2.1.22
- Fixed in:
- 2.1.23
- Disclosed:
- May 7, 2025
CVE-2025-47485 on NVD →
Cozy Blocks – A Powerful Page Builder for Gutenberg [cozy-addons] < 2.1.23
unknown
[en] Missing Authorization vulnerability in CozyThemes Cozy Blocks allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Cozy Blocks: from n/a through 2.1.22.
- Affected:
- up to 2.1.23
- Fixed in:
- 2.1.23
- Disclosed:
- May 7, 2025
CVE-2025-47485 on NVD →
Cozy Blocks <= 2.1.6 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Cozy Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.1.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that...
- CVSS:
- 6.4
- Affected:
- up to 2.1.6
- Fixed in:
- 2.1.7
- Disclosed:
- Mar 27, 2025
CVE-2025-30838 on NVD →
Cozy Blocks – A Powerful Page Builder for Gutenberg [cozy-addons] < 2.1.7
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CozyThemes Cozy Blocks allows Stored XSS. This issue affects Cozy Blocks: from n/a through 2.1.6.
- Affected:
- up to 2.1.7
- Fixed in:
- 2.1.7
- Disclosed:
- Mar 27, 2025
CVE-2025-30838 on NVD →
Cozy Blocks – A Powerful Page Builder for Gutenberg [cozy-addons] < 2.0.19
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CozyThemes Cozy Blocks allows Stored XSS.This issue affects Cozy Blocks: from n/a through 2.0.18.
- Affected:
- up to 2.0.19
- Fixed in:
- 2.0.19
- Disclosed:
- Oct 28, 2024
CVE-2024-50502 on NVD →
Cozy Blocks – A Powerful Page Builder for Gutenberg [cozy-addons] < 2.0.16
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CozyThemes Cozy Blocks allows Stored XSS.This issue affects Cozy Blocks: from n/a through 2.0.15.
- Affected:
- up to 2.0.16
- Fixed in:
- 2.0.16
- Disclosed:
- Oct 28, 2024
CVE-2024-50441 on NVD →
Cozy Blocks <= 2.0.18 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Cozy Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.0.18 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages tha...
- CVSS:
- 6.4
- Affected:
- up to 2.0.18
- Fixed in:
- 2.0.19
- Disclosed:
- Oct 25, 2024
CVE-2024-50502 on NVD →
Cozy Blocks <= 2.0.15 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Cozy Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.0.15 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages tha...
- CVSS:
- 6.4
- Affected:
- up to 2.0.15
- Fixed in:
- 2.0.16
- Disclosed:
- Oct 24, 2024
CVE-2024-50441 on NVD →
Cozy Blocks – A Powerful Page Builder for Gutenberg [cozy-addons] < 2.0.12
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CozyThemes Cozy Blocks allows Stored XSS.This issue affects Cozy Blocks: from n/a through 2.0.11.
- Affected:
- up to 2.0.12
- Fixed in:
- 2.0.12
- Disclosed:
- Oct 6, 2024
CVE-2024-47355 on NVD →
Cozy Blocks <= 2.0.11 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Cozy Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.0.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages tha...
- CVSS:
- 6.4
- Affected:
- up to 2.0.11
- Fixed in:
- 2.0.12
- Disclosed:
- Sep 30, 2024
CVE-2024-47355 on NVD →
Freemius SDK <= 2.5.9 - Reflected Cross-Site Scripting via fs_request_get
medium
The Freemius SDK for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘fs_request_get’ function in versions up to, and including, 2.5.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute...
- CVSS:
- 6.1
- Affected:
- up to 1.2.3
- Fixed in:
- 1.2.4
- Disclosed:
- Jul 18, 2023
CVE-2023-33999 on NVD →
Cozy Blocks – A Powerful Page Builder for Gutenberg [cozy-addons] < 1.2.4
unknown
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
- Affected:
- up to 1.2.4
- Fixed in:
- 1.2.4
CVE-2023-33999 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database