Frontis Blocks <= 1.1.6 - Unauthenticated Server-Side Request Forgery via 'url' Parameter
high
The Frontis Blocks plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.1.6. This is due to insufficient restriction on the 'url' parameter in the 'template_proxy' function. This makes it possible for unauthenticated attackers to make web requests to arbitrary locati...
- CVSS:
- 7.2
- Affected:
- up to 1.1.6
- Fixed in:
- 1.1.7
- Disclosed:
- Jan 23, 2026
CVE-2026-0807 on NVD →
Frontis Blocks <= 1.1.5 - Unauthenticated Server-Side Request Forgery
medium
The Frontis Blocks — Block Library for the Block Editor plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.1.5. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application which can be used t...
- CVSS:
- 6.5
- Affected:
- up to 1.1.5
- Fixed in:
- 1.1.6
- Disclosed:
- Jan 20, 2026
CVE-2025-68030 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database