Getwid <= 2.1.2 - Authenticated (Contributor+) Sensitive Information Exposure
medium
The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1.2. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive user or configuration data.
- CVSS:
- 4.3
- Affected:
- up to 2.1.2
- Fixed in:
- 2.1.3
- Disclosed:
- Sep 22, 2025
CVE-2025-58252 on NVD →
Getwid – Gutenberg Blocks [getwid] < 2.0.12
unknown
[en] Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled FancyBox JavaScript library (versions 1.3.4 to 3.5.7) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,...
- Affected:
- up to 2.0.12
- Fixed in:
- 2.0.12
- Disclosed:
- Dec 4, 2024
CVE-2024-5020 on NVD →
Multiple Plugins <= (Various Versions) - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via FancyBox JavaScript Library
medium
Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled FancyBox JavaScript library (versions 1.3.4 to 3.5.7) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with...
- CVSS:
- 6.4
- Affected:
- up to 2.0.11
- Fixed in:
- 2.0.12
- Disclosed:
- Dec 3, 2024
CVE-2024-5020 on NVD →
Getwid – Gutenberg Blocks [getwid] < 2.0.13
unknown
[en] The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `template-post-custom-field` block in all versions up to, and including, 2.0.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-le...
- Affected:
- up to 2.0.13
- Fixed in:
- 2.0.13
- Disclosed:
- Nov 20, 2024
CVE-2024-10872 on NVD →
Getwid – Gutenberg Blocks <= 2.0.12 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `template-post-custom-field` block in all versions up to, and including, 2.0.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level a...
- CVSS:
- 6.4
- Affected:
- up to 2.0.12
- Fixed in:
- 2.0.13
- Disclosed:
- Nov 19, 2024
CVE-2024-10872 on NVD →
Getwid – Gutenberg Blocks [getwid] < 2.0.11
unknown
[en] The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the get_google_api_key function in all versions up to, and including, 2.0.10. This makes it possible for authenticated attackers, with Contributor-level access and above, to se...
- Affected:
- up to 2.0.11
- Fixed in:
- 2.0.11
- Disclosed:
- Jul 20, 2024
CVE-2024-6489 on NVD →
Getwid – Gutenberg Blocks [getwid] < 2.0.11
unknown
[en] The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the mailchimp_api_key_manage function in all versions up to, and including, 2.0.10. This makes it possible for authenticated attackers, with Contributor-level access and above,...
- Affected:
- up to 2.0.11
- Fixed in:
- 2.0.11
- Disclosed:
- Jul 20, 2024
CVE-2024-6491 on NVD →
Getwid – Gutenberg Blocks <= 2.0.10 - Missing Authentication to MailChimp API key update
medium
The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the mailchimp_api_key_manage function in all versions up to, and including, 2.0.10. This makes it possible for authenticated attackers, with Contributor-level access and above, to s...
- CVSS:
- 4.3
- Affected:
- up to 2.0.10
- Fixed in:
- 2.0.11
- Disclosed:
- Jul 19, 2024
CVE-2024-6491 on NVD →
Getwid – Gutenberg Blocks <= 2.0.10 - Missing Authorization to Google API key update
medium
The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the get_google_api_key function in all versions up to, and including, 2.0.10. This makes it possible for authenticated attackers, with Contributor-level access and above, to set the...
- CVSS:
- 5.3
- Affected:
- up to 2.0.10
- Fixed in:
- 2.0.11
- Disclosed:
- Jul 19, 2024
CVE-2024-6489 on NVD →
Getwid – Gutenberg Blocks [getwid] < 2.0.8
unknown
[en] The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Countdown block in all versions up to, and including, 2.0.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, wi...
- Affected:
- up to 2.0.8
- Fixed in:
- 2.0.8
- Disclosed:
- May 2, 2024
CVE-2024-3588 on NVD →
Getwid – Gutenberg Blocks <= 2.0.7 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via 'Countdown'
medium
The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Countdown block in all versions up to, and including, 2.0.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with co...
- CVSS:
- 6.4
- Affected:
- up to 2.0.7
- Fixed in:
- 2.0.8
- Disclosed:
- Apr 26, 2024
CVE-2024-3588 on NVD →
Getwid – Gutenberg Blocks [getwid] < 2.0.6
unknown
[en] The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the block content in all versions up to, and including, 2.0.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access and above, to inj...
- Affected:
- up to 2.0.6
- Fixed in:
- 2.0.6
- Disclosed:
- Apr 9, 2024
CVE-2024-1948 on NVD →
Getwid – Gutenberg Blocks <= 2.0.5 - Authenticated(Contributor+) Stored Cross-Site Scripting via Block Content
medium
The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the block content in all versions up to, and including, 2.0.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access and above, to inject a...
- CVSS:
- 6.4
- Affected:
- up to 2.0.5
- Fixed in:
- 2.0.6
- Disclosed:
- Mar 21, 2024
CVE-2024-1948 on NVD →
Getwid – Gutenberg Blocks [getwid] < 2.0.5
unknown
[en] The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the recaptcha_api_key_manage function in all versions up to, and including, 2.0.3. This makes it possible for authenticated attackers, with subscriber-level access and above, t...
- Affected:
- up to 2.0.5
- Fixed in:
- 2.0.5
- Disclosed:
- Feb 5, 2024
CVE-2023-6959 on NVD →
Getwid – Gutenberg Blocks [getwid] < 2.0.5
unknown
[en] The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to CAPTCHA Bypass in versions up to, and including, 2.0.4. This makes it possible for unauthenticated attackers to bypass the Captcha Verification of the Contact Form block by omitting 'g-recaptcha-response' from the 'data' array.
- Affected:
- up to 2.0.5
- Fixed in:
- 2.0.5
- Disclosed:
- Feb 5, 2024
CVE-2023-6963 on NVD →
Getwid – Gutenberg Blocks <= 2.0.4 - Captcha Bypass
medium
The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to CAPTCHA Bypass in versions up to, and including, 2.0.4. This makes it possible for unauthenticated attackers to bypass the Captcha Verification of the Contact Form block by omitting 'g-recaptcha-response' from the 'data' array.
- CVSS:
- 5.3
- Affected:
- up to 2.0.4
- Fixed in:
- 2.0.5
- Disclosed:
- Jan 17, 2024
CVE-2023-6963 on NVD →
Getwid – Gutenberg Blocks <= 2.0.4 - Missing Authorization to Recaptcha API Key Modification
medium
The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the recaptcha_api_key_manage function in all versions up to, and including, 2.0.3. This makes it possible for authenticated attackers, with subscriber-level access and above, to add...
- CVSS:
- 4.3
- Affected:
- up to 2.0.4
- Fixed in:
- 2.0.5
- Disclosed:
- Jan 17, 2024
CVE-2023-6959 on NVD →
Getwid – Gutenberg Blocks [getwid] < 2.0.3
unknown
[en] Any unauthenticated user may send e-mail from the site with any title or content to the admin
- Affected:
- up to 2.0.3
- Fixed in:
- 2.0.3
- Disclosed:
- Jan 8, 2024
CVE-2023-6042 on NVD →
Getwid – Gutenberg Blocks <= 2.0.2 - Improper Input Validation to Arbitrary Email Sending to Admin
medium
The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized arbitrary email sending due to insufficient limitations on the content of emails sent in all versions up to, and including, 2.0.2. This makes it possible for unauthenticated attackers to send emails to the site admin with arbitrary content...
- CVSS:
- 5.3
- Affected:
- up to 2.0.2
- Fixed in:
- 2.0.3
- Disclosed:
- Dec 15, 2023
CVE-2023-6042 on NVD →
Getwid – Gutenberg Blocks [getwid] < 1.8.4
unknown
[en] The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to Server Side Request Forgery via the get_remote_content REST API endpoint in versions up to, and including, 1.8.3. This can allow authenticated attackers with subscriber-level permissions or above to make web requests to arbitrary locations origina...
- Affected:
- up to 1.8.4
- Fixed in:
- 1.8.4
- Disclosed:
- Jun 9, 2023
CVE-2023-1895 on NVD →
Getwid – Gutenberg Blocks [getwid] < 1.8.4
unknown
[en] The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized modification of data due to an insufficient capability check on the get_remote_templates function in versions up to, and including, 1.8.3. This makes it possible for authenticated attackers with subscriber-level permissions or above t...
- Affected:
- up to 1.8.4
- Fixed in:
- 1.8.4
- Disclosed:
- Jun 9, 2023
CVE-2023-1910 on NVD →
Getwid – Gutenberg Blocks <= 1.8.3 - Authenticated(Subscriber+) Server Side Request Forgery
high
The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to Server Side Request Forgery via the get_remote_content REST API endpoint in versions up to, and including, 1.8.3. This can allow authenticated attackers with subscriber-level permissions or above to make web requests to arbitrary locations originating...
- CVSS:
- 8.5
- Affected:
- up to 1.8.3
- Fixed in:
- 1.8.4
- Disclosed:
- Jun 6, 2023
CVE-2023-1895 on NVD →
Getwid – Gutenberg Blocks <= 1.8.3 - Improper Authorization via get_remote_templates REST endpoint
medium
The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized modification of data due to an insufficient capability check on the get_remote_templates function in versions up to, and including, 1.8.3. This makes it possible for authenticated attackers with subscriber-level permissions or above to flu...
- CVSS:
- 4.3
- Affected:
- up to 1.8.3
- Fixed in:
- 1.8.4
- Disclosed:
- Jun 6, 2023
CVE-2023-1910 on NVD →
Getwid – Gutenberg Blocks [getwid] < 1.7.7
unknown
Cross-Site Request Forgery (CSRF) / Settings Change vulnerability discovered in WordPress Getwid – Gutenberg Blocks plugin (versions <= 1.7.4).
- Affected:
- up to 1.7.7
- Fixed in:
- 1.7.7
- Disclosed:
- Sep 21, 2021
Getwid – Gutenberg Blocks [getwid] < 1.7.7
unknown
Authenticated Information Disclosure vulnerability discovered in WordPress Getwid – Gutenberg Blocks plugin (versions <= 1.7.4).
- Affected:
- up to 1.7.7
- Fixed in:
- 1.7.7
- Disclosed:
- Sep 21, 2021
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database