plugin

Essential Blocks Vulnerabilities

62 known security issues reported for the Essential Blocks WordPress plugin. Most recent disclosed Aug 3, 2026.

1 critical 3 high 29 medium

Running Essential Blocks on your site? Check whether your installed version is affected.

Scan your site free

Essential Blocks <= 6.3.0 - Unauthenticated Information Exposure

medium

The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.3.0. This makes it possible for unauthenticated attackers to extract non-public custom post type data.

CVSS:
5.3
Affected:
up to 6.3.0
Fixed in:
6.4.0
Disclosed:
Aug 3, 2026

CVE-2026-13154 on NVD →

Essential Blocks <= 6.3.0 - Unauthenticated Information Exposure

medium

The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.3.0. This makes it possible for unauthenticated attackers to extract sales data.

CVSS:
5.3
Affected:
up to 6.3.0
Fixed in:
6.4.0
Disclosed:
Aug 3, 2026

CVE-2026-13153 on NVD →

Gutenberg Essential Blocks - Page Builder for Gutenberg Blocks & Patterns <= 6.1.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'configurablePrefix' Block Attribute

medium

The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'configurablePrefix' Block Attribute in all versions up to, and including, 6.1.4 due to insufficient input sanitization and output escaping. This makes it possible for...

CVSS:
6.4
Affected:
up to 6.1.4
Fixed in:
6.2.0
Disclosed:
Jun 24, 2026

CVE-2026-10833 on NVD →

Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns <= 6.1.3 - Authenticated (Author+) Server-Side Request Forgery

high

The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6.1.3 via the `save_ai_generated_image()` function. This makes it possible for authenticated attackers, with Author-level access and above...

CVSS:
7.2
Affected:
up to 6.1.3
Fixed in:
6.1.4
Disclosed:
Jun 4, 2026

CVE-2026-10586 on NVD →

Gutenberg Essential Blocks <= 6.0.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Block Attributes

medium

The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the className, classHook, and blockId attributes in the Add to Cart block (essential-blocks/add-to-cart) in all versions up to, and including, 6.0.4. This is due to insufficie...

CVSS:
6.4
Affected:
up to 6.0.4
Fixed in:
6.1.0
Disclosed:
May 1, 2026

CVE-2026-4658 on NVD →

Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks &amp; Patterns [essential-blocks] < 5.7.3

unknown

[en] The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to unauthorized access of data due to a missing or incorrect capability checks on the get_instagram_access_token_callback, google_map_api_key_save_callback and get_siteinfo functions in all versions up...

Affected:
up to 5.7.3
Fixed in:
5.7.3
Disclosed:
Dec 17, 2025

CVE-2025-11369 on NVD →

Essential Blocks <= 5.7.2 - Missing Authorization To Authenticated (Author+) Information Disclosure

medium

The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to unauthorized access of data due to a missing or incorrect capability checks on the get_instagram_access_token_callback, google_map_api_key_save_callback and get_siteinfo functions in all versions up to, a...

CVSS:
4.3
Affected:
up to 5.7.2
Fixed in:
5.7.3
Disclosed:
Dec 16, 2025

CVE-2025-11369 on NVD →

Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks &amp; Patterns [essential-blocks] < 5.7.2

unknown

[en] The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'titleTag' attribute in all versions up to, and including, 5.7.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticat...

Affected:
up to 5.7.2
Fixed in:
5.7.2
Disclosed:
Oct 18, 2025

CVE-2025-11270 on NVD →

Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks &amp; Patterns [essential-blocks] < 5.7.2

unknown

[en] The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5.7.1 via the eb_save_ai_generated_image function. This makes it possible for authenticated attackers, with Author-level access and a...

Affected:
up to 5.7.2
Fixed in:
5.7.2
Disclosed:
Oct 18, 2025

CVE-2025-11361 on NVD →

Essential Blocks <= 5.7.1 - Authenticated (Author+) Server-Side Request Forgery

medium

The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5.7.1 via the eb_save_ai_generated_image function. This makes it possible for authenticated attackers, with Author-level access and above,...

CVSS:
6.4
Affected:
up to 5.7.1
Fixed in:
5.7.2
Disclosed:
Oct 17, 2025

CVE-2025-11361 on NVD →

Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns <= 5.7.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'titleTag' attribute in all versions up to, and including, 5.7.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated at...

CVSS:
6.4
Affected:
up to 5.7.1
Fixed in:
5.7.2
Disclosed:
Oct 17, 2025

CVE-2025-11270 on NVD →

Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates <= 5.4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Slider and Post Carousel Widgets

medium

The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via HTML attributes in Slider and Post Carousel widgets in all versions up to, and including, 5.4.0 due to insufficient input sanitization and output escaping. This makes it possi...

CVSS:
6.4
Affected:
up to 5.4.0
Fixed in:
5.4.1
Disclosed:
May 26, 2025

CVE-2025-4682 on NVD →

Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates <= 5.3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Parallax slider in all versions up to, and including, 5.3.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,...

CVSS:
6.4
Affected:
up to 5.3.1
Fixed in:
5.3.2
Disclosed:
Mar 7, 2025

CVE-2025-1664 on NVD →

Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks &amp; Patterns [essential-blocks] < 5.3.0

unknown

[en] The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data-marker’ parameter in all versions up to, and including, 5.2.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticat...

Affected:
up to 5.3.0
Fixed in:
5.3.0
Disclosed:
Feb 26, 2025

CVE-2024-13803 on NVD →

Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates <= 5.2.3 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data-marker’ parameter in all versions up to, and including, 5.2.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated at...

CVSS:
6.4
Affected:
up to 5.2.3
Fixed in:
5.3.0
Disclosed:
Feb 25, 2025

CVE-2024-13803 on NVD →

Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks &amp; Patterns [essential-blocks] < 4.8.4

unknown

[en] Missing Authorization vulnerability in WPDeveloper Essential Blocks for Gutenberg allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Essential Blocks for Gutenberg: from n/a through 4.8.3.

Affected:
up to 4.8.4
Fixed in:
4.8.4
Disclosed:
Feb 25, 2025

CVE-2025-26871 on NVD →

Essential Blocks for Gutenberg <= 4.8.3 - Missing Authorization

medium

The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 4.8.3. This makes it possible for authenticated attackers, with Contributor-level access and above, t...

CVSS:
4.3
Affected:
up to 4.8.3
Fixed in:
4.8.4
Disclosed:
Feb 22, 2025

CVE-2025-26871 on NVD →

Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks &amp; Patterns [essential-blocks] < 5.1.1

unknown

[en] The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the maker title value of the Google Maps block in all versions up to, and including, 5.0.9 due to insufficient input sanitization and output escaping. This makes it poss...

Affected:
up to 5.1.1
Fixed in:
5.1.1
Disclosed:
Jan 8, 2025

CVE-2024-12045 on NVD →

Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates <= 5.0.9 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the maker title value of the Google Maps block in all versions up to, and including, 5.0.9 due to insufficient input sanitization and output escaping. This makes it possible...

CVSS:
4.4
Affected:
up to 5.1.0
Fixed in:
5.1.1
Disclosed:
Jan 7, 2025

CVE-2024-12045 on NVD →

Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks &amp; Patterns [essential-blocks] < 3.8.6

unknown

[en] Missing Authorization vulnerability in WPDeveloper Essential Blocks for Gutenberg allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Essential Blocks for Gutenberg: from n/a through 3.8.5.

Affected:
up to 3.8.6
Fixed in:
3.8.6
Disclosed:
Dec 13, 2024

CVE-2022-47594 on NVD →

Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks &amp; Patterns [essential-blocks] < 4.2.1

unknown

[en] Missing Authorization vulnerability in WPDeveloper Essential Blocks for Gutenberg allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Essential Blocks for Gutenberg: from n/a through 4.2.0.

Affected:
up to 4.2.1
Fixed in:
4.2.1
Disclosed:
Dec 9, 2024

CVE-2023-47760 on NVD →

Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks &amp; Patterns [essential-blocks] < 4.2.1

unknown

[en] Missing Authorization vulnerability in WPDeveloper Essential Blocks for Gutenberg allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Essential Blocks for Gutenberg: from n/a through 4.2.0.

Affected:
up to 4.2.1
Fixed in:
4.2.1
Disclosed:
Dec 9, 2024

CVE-2023-51359 on NVD →

Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks &amp; Patterns [essential-blocks] < 4.2.1

unknown

[en] Missing Authorization vulnerability in WPDeveloper Essential Blocks for Gutenberg allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Essential Blocks for Gutenberg: from n/a through 4.2.0.

Affected:
up to 4.2.1
Fixed in:
4.2.1
Disclosed:
Dec 9, 2024

CVE-2023-51360 on NVD →

Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks &amp; Patterns [essential-blocks] < 4.9.0

unknown

[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPDeveloper Essential Blocks for Gutenberg allows Stored XSS.This issue affects Essential Blocks for Gutenberg: from n/a through 4.8.4.

Affected:
up to 4.9.0
Fixed in:
4.9.0
Disclosed:
Oct 5, 2024

CVE-2024-47385 on NVD →

Essential Blocks for Gutenberg <= 4.8.4 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Essential Blocks for Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.8.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web sc...

CVSS:
6.4
Affected:
up to 4.8.4
Fixed in:
4.9.0
Disclosed:
Sep 30, 2024

CVE-2024-47385 on NVD →

Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks &amp; Patterns [essential-blocks] < 4.7.0

unknown

[en] The Essential Blocks WordPress plugin before 4.7.0 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

Affected:
up to 4.7.0
Fixed in:
4.7.0
Disclosed:
Aug 2, 2024

CVE-2024-5595 on NVD →

Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates <= 4.6.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'post-carousel' block in all versions up to, and including, 4.6.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it pos...

CVSS:
6.4
Affected:
up to 4.6.1
Fixed in:
4.7.0
Disclosed:
Jul 12, 2024

CVE-2024-5595 on NVD →

Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks &amp; Patterns [essential-blocks] < 4.4.10

unknown

[en] Missing Authorization vulnerability in WPDeveloper Essential Blocks for Gutenberg.This issue affects Essential Blocks for Gutenberg: from n/a through 4.4.9.

Affected:
up to 4.4.10
Fixed in:
4.4.10
Disclosed:
Jun 9, 2024

CVE-2024-30467 on NVD →

Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks &amp; Patterns [essential-blocks] < 4.5.13

unknown

[en] The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘tagName’ parameter in versions up to, and including, 4.5.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated atta...

Affected:
up to 4.5.13
Fixed in:
4.5.13
Disclosed:
May 18, 2024

CVE-2024-4891 on NVD →

Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates <= 4.5.12 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘tagName’ parameter in versions up to, and including, 4.5.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers...

CVSS:
6.4
Affected:
up to 4.5.12
Fixed in:
4.5.13
Disclosed:
May 16, 2024

CVE-2024-4891 on NVD →

Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks &amp; Patterns [essential-blocks] < 4.5.10

unknown

[en] The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's "Social Icons" block in all versions up to, and including, 4.5.9 due to insufficient input sanitization and output escaping on user supplied attributes. This...

Affected:
up to 4.5.10
Fixed in:
4.5.10
Disclosed:
Apr 19, 2024

CVE-2024-3818 on NVD →

Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates <= 4.5.9 - Authenticated (Contributor+) DOM-Based Cross-Site Scripting via "Social Icons" Block

medium

The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's "Social Icons" block in all versions up to, and including, 4.5.9 due to insufficient input sanitization and output escaping on user supplied attributes. This make...

CVSS:
5.4
Affected:
up to 4.5.9
Fixed in:
4.5.10
Disclosed:
Apr 18, 2024

CVE-2024-3818 on NVD →

Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks &amp; Patterns [essential-blocks] < 4.5.4

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPDeveloper Essential Blocks for Gutenberg allows Stored XSS.This issue affects Essential Blocks for Gutenberg: from n/a through 4.5.3.

Affected:
up to 4.5.4
Fixed in:
4.5.4
Disclosed:
Apr 7, 2024

CVE-2024-31306 on NVD →

Essential Blocks for Gutenberg <= 4.5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Essential Blocks for Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.5.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web sc...

CVSS:
6.4
Affected:
up to 4.5.3
Fixed in:
4.5.4
Disclosed:
Apr 5, 2024

CVE-2024-31306 on NVD →

Essential Blocks for Gutenberg <= 4.4.9 - Missing Authorization

medium

The Essential Blocks for Gutenberg plugin for WordPress is vulnerable to unauthorized access due to a missing capability check in versions up to, and including, 4.4.9. This makes it possible for authenticated attackers, with contributor-level access and above, to perform unauthorized actions.

CVSS:
4.3
Affected:
up to 4.4.9
Fixed in:
4.4.10
Disclosed:
Mar 28, 2024

CVE-2024-30467 on NVD →

Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks &amp; Patterns [essential-blocks] < 4.5.4

unknown

[en] The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets in all versions up to, and including, 4.5.2 due to insufficient input sanitization and output escaping on user supplied attributes such as listStyle....

Affected:
up to 4.5.4
Fixed in:
4.5.4
Disclosed:
Mar 20, 2024

CVE-2024-2255 on NVD →

Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates <= 4.5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets in all versions up to, and including, 4.5.3 due to insufficient input sanitization and output escaping on user supplied attributes such as listStyle. This...

CVSS:
6.4
Affected:
up to 4.5.3
Fixed in:
4.5.4
Disclosed:
Mar 19, 2024

CVE-2024-2255 on NVD →

Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks &amp; Patterns [essential-blocks] < 4.5.2

unknown

[en] The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the blockId parameter in all versions up to, and including, 4.5.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated att...

Affected:
up to 4.5.2
Fixed in:
4.5.2
Disclosed:
Mar 13, 2024

CVE-2024-1854 on NVD →

Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates <= 4.5.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the blockId parameter in all versions up to, and including, 4.5.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attacker...

CVSS:
6.4
Affected:
up to 4.5.1
Fixed in:
4.5.2
Disclosed:
Feb 28, 2024

CVE-2024-1854 on NVD →

Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks &amp; Patterns [essential-blocks] < 4.4.3

unknown

[en] The Essential Blocks WordPress plugin before 4.4.3 does not prevent unauthenticated attackers from overwriting local variables when rendering templates over the REST API, which may lead to Local File Inclusion attacks.

Affected:
up to 4.4.3
Fixed in:
4.4.3
Disclosed:
Jan 15, 2024

CVE-2023-6623 on NVD →

Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks &amp; Patterns [essential-blocks] < 4.4.7

unknown

[en] The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Table of Contents block in all versions up to, and including, 4.4.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticat...

Affected:
up to 4.4.7
Fixed in:
4.4.7
Disclosed:
Jan 11, 2024

CVE-2023-7071 on NVD →

Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates <= 4.4.6 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Table of Contents block in all versions up to, and including, 4.4.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated at...

CVSS:
6.4
Affected:
up to 4.4.6
Fixed in:
4.4.7
Disclosed:
Jan 9, 2024

CVE-2023-7071 on NVD →

Essential Blocks for Gutenberg <= 4.2.0 - Incorrect Authorization Checks

medium

The Essential Blocks for Gutenberg plugin for WordPress is vulnerable to unauthorized modification of data due to improper capability checks on various functions function in versions up to, and including, 4.2.0. This makes it possible for authenticated attackers, with contributor-level access and above, to perform unau...

CVSS:
5.4
Affected:
up to 4.2.0
Fixed in:
4.2.1
Disclosed:
Dec 26, 2023

CVE-2023-51359 on NVD →

Essential Blocks <= 4.4.2 - Unauthenticated Local File Inclusion

critical

The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.4.2 via the /wp-json/essential-blocks/v1/queries REST API endpoint. This makes it possible for unauthenticated attackers to include and execute ar...

CVSS:
9.8
Affected:
up to 4.4.2
Fixed in:
4.4.3
Disclosed:
Dec 21, 2023

CVE-2023-6623 on NVD →

Essential Blocks for Gutenberg <= 4.2.0 - Missing Authorization via AJAX actions

medium

The Essential Blocks for Gutenberg plugin for WordPress is vulnerable to unauthorized access to AJAX actions due to a missing capability check on several functions in versions up to, and including, 4.2.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to invoke those functio...

CVSS:
4.3
Affected:
up to 4.2.0
Fixed in:
4.2.1
Disclosed:
Nov 13, 2023

CVE-2023-47760 on NVD →

Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks &amp; Patterns [essential-blocks] < 4.2.1

unknown

[en] The Essential Blocks plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.2.0 via deserialization of untrusted input in the get_products function. This allows unauthenticated attackers to inject a PHP Object. No POP chain is present in the vulnerable plugin. If a POP chain...

Affected:
up to 4.2.1
Fixed in:
4.2.1
Disclosed:
Oct 20, 2023

CVE-2023-4402 on NVD →

Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks &amp; Patterns [essential-blocks] < 4.2.1

unknown

[en] The Essential Blocks plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.2.0 via deserialization of untrusted input in the get_posts function. This allows unauthenticated attackers to inject a PHP Object. No POP chain is present in the vulnerable plugin. If a POP chain is...

Affected:
up to 4.2.1
Fixed in:
4.2.1
Disclosed:
Oct 20, 2023

CVE-2023-4386 on NVD →

Essential Blocks <= 4.2.0 - Unauthenticated PHP Object Injection via queries

high

The Essential Blocks plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.2.0 via deserialization of untrusted input in the get_posts function. This allows unauthenticated attackers to inject a PHP Object. No POP chain is present in the vulnerable plugin. If a POP chain is pres...

CVSS:
8.1
Affected:
up to 4.2.0
Fixed in:
4.2.1
Disclosed:
Sep 13, 2023

CVE-2023-4386 on NVD →

Essential Blocks <= 4.2.0 - Unauthenticated PHP Object Injection via products

high

The Essential Blocks plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.2.0 via deserialization of untrusted input in the get_products function. This allows unauthenticated attackers to inject a PHP Object. No POP chain is present in the vulnerable plugin. If a POP chain is p...

CVSS:
8.1
Affected:
up to 4.2.0
Fixed in:
4.2.1
Disclosed:
Sep 13, 2023

CVE-2023-4402 on NVD →

Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks &amp; Patterns [essential-blocks] < 4.0.7

unknown

[en] The Essential Blocks plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.0.6. This is due to missing or incorrect nonce validation on the save function. This makes it possible for unauthenticated attackers to change plugin settings via a forged request granted they...

Affected:
up to 4.0.7
Fixed in:
4.0.7
Disclosed:
Jun 9, 2023

CVE-2023-2087 on NVD →

Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks &amp; Patterns [essential-blocks] < 4.0.7

unknown

[en] The Essential Blocks plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check on the save function in versions up to, and including, 4.0.6. This makes it possible for subscriber-level attackers to save plugin settings. While a nonce check is present, it is only exec...

Affected:
up to 4.0.7
Fixed in:
4.0.7
Disclosed:
Jun 9, 2023

CVE-2023-2083 on NVD →

Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks &amp; Patterns [essential-blocks] < 4.0.7

unknown

[en] The Essential Blocks plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check on the get function in versions up to, and including, 4.0.6. This makes it possible for subscriber-level attackers to obtain plugin settings. While a nonce check is present, it is only exe...

Affected:
up to 4.0.7
Fixed in:
4.0.7
Disclosed:
Jun 9, 2023

CVE-2023-2084 on NVD →

Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks &amp; Patterns [essential-blocks] < 4.0.7

unknown

[en] The Essential Blocks plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check on the template_count function in versions up to, and including, 4.0.6. This makes it possible for subscriber-level attackers to obtain plugin template information. While a nonce check is...

Affected:
up to 4.0.7
Fixed in:
4.0.7
Disclosed:
Jun 9, 2023

CVE-2023-2086 on NVD →

Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks &amp; Patterns [essential-blocks] < 4.0.7

unknown

[en] The Essential Blocks plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check on the templates function in versions up to, and including, 4.0.6. This makes it possible for subscriber-level attackers to obtain plugin template information. While a nonce check is prese...

Affected:
up to 4.0.7
Fixed in:
4.0.7
Disclosed:
Jun 9, 2023

CVE-2023-2085 on NVD →

Essential Blocks <= 4.0.6 - Missing Authorization via get

medium

The Essential Blocks plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check on the get function in versions up to, and including, 4.0.6. This makes it possible for subscriber-level attackers to obtain plugin settings. While a nonce check is present, it is only executed...

CVSS:
4.3
Affected:
up to 4.0.6
Fixed in:
4.0.7
Disclosed:
Apr 18, 2023

CVE-2023-2084 on NVD →

Essential Blocks <= 4.0.6 - Missing Authorization via save

medium

The Essential Blocks plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check on the save function in versions up to, and including, 4.0.6. This makes it possible for subscriber-level attackers to save plugin settings. While a nonce check is present, it is only executed...

CVSS:
4.3
Affected:
up to 4.0.6
Fixed in:
4.0.7
Disclosed:
Apr 18, 2023

CVE-2023-2083 on NVD →

Essential Blocks <= 4.0.6 - Cross-Site Request Forgery via save

medium

The Essential Blocks plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.0.6. This is due to missing or incorrect nonce validation on the save function. This makes it possible for unauthenticated attackers to change plugin settings via a forged request granted they can t...

CVSS:
4.3
Affected:
up to 4.0.6
Fixed in:
4.0.7
Disclosed:
Apr 18, 2023

CVE-2023-2087 on NVD →

Essential Blocks <= 4.0.6 - Missing Authorization via templates

medium

The Essential Blocks plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check on the templates function in versions up to, and including, 4.0.6. This makes it possible for subscriber-level attackers to obtain plugin template information. While a nonce check is present, i...

CVSS:
4.3
Affected:
up to 4.0.6
Fixed in:
4.0.7
Disclosed:
Apr 18, 2023

CVE-2023-2085 on NVD →

Essential Blocks <= 4.0.6 - Missing Authorization via template_count

medium

The Essential Blocks plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check on the template_count function in versions up to, and including, 4.0.6. This makes it possible for subscriber-level attackers to obtain plugin template information. While a nonce check is prese...

CVSS:
4.3
Affected:
up to 4.0.6
Fixed in:
4.0.7
Disclosed:
Apr 18, 2023

CVE-2023-2086 on NVD →

Essential Blocks for Gutenberg <= 3.8.5 - Cross-Site Request Forgery

medium

The Essential Blocks for Gutenberg plugin for WordPress is vulnerable to authorization bypass due to incorrectly defined capability checks throughout the 'EB_Openverse_Ajax' class in versions up to, and including, 3.8.5. This makes it possible for unauthenticated attackers to register Openverse clients, upload images,...

CVSS:
4.3
Affected:
up to 3.8.5
Fixed in:
3.8.6
Disclosed:
Jan 20, 2023

CVE-2022-47594 on NVD →

Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks &amp; Patterns [essential-blocks] < 5.3.2

unknown
Affected:
up to 5.3.2
Fixed in:
5.3.2

CVE-2025-1664 on NVD →

Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks &amp; Patterns [essential-blocks] < 5.4.1

unknown
Affected:
up to 5.4.1
Fixed in:
5.4.1

CVE-2025-4682 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database