plugin

Getwid Vulnerabilities

25 known security issues reported for the Getwid WordPress plugin. Most recent disclosed Sep 22, 2025.

1 high 11 medium

Running Getwid on your site? Check whether your installed version is affected.

Scan your site free

Getwid <= 2.1.2 - Authenticated (Contributor+) Sensitive Information Exposure

medium

The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1.2. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive user or configuration data.

CVSS:
4.3
Affected:
up to 2.1.2
Fixed in:
2.1.3
Disclosed:
Sep 22, 2025

CVE-2025-58252 on NVD →

Getwid &#8211; Gutenberg Blocks [getwid] < 2.0.12

unknown

[en] Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled FancyBox JavaScript library (versions 1.3.4 to 3.5.7) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,...

Affected:
up to 2.0.12
Fixed in:
2.0.12
Disclosed:
Dec 4, 2024

CVE-2024-5020 on NVD →

Multiple Plugins <= (Various Versions) - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via FancyBox JavaScript Library

medium

Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled FancyBox JavaScript library (versions 1.3.4 to 3.5.7) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with...

CVSS:
6.4
Affected:
up to 2.0.11
Fixed in:
2.0.12
Disclosed:
Dec 3, 2024

CVE-2024-5020 on NVD →

Getwid &#8211; Gutenberg Blocks [getwid] < 2.0.13

unknown

[en] The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `template-post-custom-field` block in all versions up to, and including, 2.0.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-le...

Affected:
up to 2.0.13
Fixed in:
2.0.13
Disclosed:
Nov 20, 2024

CVE-2024-10872 on NVD →

Getwid – Gutenberg Blocks <= 2.0.12 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `template-post-custom-field` block in all versions up to, and including, 2.0.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level a...

CVSS:
6.4
Affected:
up to 2.0.12
Fixed in:
2.0.13
Disclosed:
Nov 19, 2024

CVE-2024-10872 on NVD →

Getwid &#8211; Gutenberg Blocks [getwid] < 2.0.11

unknown

[en] The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the get_google_api_key function in all versions up to, and including, 2.0.10. This makes it possible for authenticated attackers, with Contributor-level access and above, to se...

Affected:
up to 2.0.11
Fixed in:
2.0.11
Disclosed:
Jul 20, 2024

CVE-2024-6489 on NVD →

Getwid &#8211; Gutenberg Blocks [getwid] < 2.0.11

unknown

[en] The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the mailchimp_api_key_manage function in all versions up to, and including, 2.0.10. This makes it possible for authenticated attackers, with Contributor-level access and above,...

Affected:
up to 2.0.11
Fixed in:
2.0.11
Disclosed:
Jul 20, 2024

CVE-2024-6491 on NVD →

Getwid – Gutenberg Blocks <= 2.0.10 - Missing Authentication to MailChimp API key update

medium

The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the mailchimp_api_key_manage function in all versions up to, and including, 2.0.10. This makes it possible for authenticated attackers, with Contributor-level access and above, to s...

CVSS:
4.3
Affected:
up to 2.0.10
Fixed in:
2.0.11
Disclosed:
Jul 19, 2024

CVE-2024-6491 on NVD →

Getwid – Gutenberg Blocks <= 2.0.10 - Missing Authorization to Google API key update

medium

The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the get_google_api_key function in all versions up to, and including, 2.0.10. This makes it possible for authenticated attackers, with Contributor-level access and above, to set the...

CVSS:
5.3
Affected:
up to 2.0.10
Fixed in:
2.0.11
Disclosed:
Jul 19, 2024

CVE-2024-6489 on NVD →

Getwid &#8211; Gutenberg Blocks [getwid] < 2.0.8

unknown

[en] The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Countdown block in all versions up to, and including, 2.0.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, wi...

Affected:
up to 2.0.8
Fixed in:
2.0.8
Disclosed:
May 2, 2024

CVE-2024-3588 on NVD →

Getwid – Gutenberg Blocks <= 2.0.7 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via 'Countdown'

medium

The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Countdown block in all versions up to, and including, 2.0.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with co...

CVSS:
6.4
Affected:
up to 2.0.7
Fixed in:
2.0.8
Disclosed:
Apr 26, 2024

CVE-2024-3588 on NVD →

Getwid &#8211; Gutenberg Blocks [getwid] < 2.0.6

unknown

[en] The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the block content in all versions up to, and including, 2.0.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access and above, to inj...

Affected:
up to 2.0.6
Fixed in:
2.0.6
Disclosed:
Apr 9, 2024

CVE-2024-1948 on NVD →

Getwid – Gutenberg Blocks <= 2.0.5 - Authenticated(Contributor+) Stored Cross-Site Scripting via Block Content

medium

The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the block content in all versions up to, and including, 2.0.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access and above, to inject a...

CVSS:
6.4
Affected:
up to 2.0.5
Fixed in:
2.0.6
Disclosed:
Mar 21, 2024

CVE-2024-1948 on NVD →

Getwid &#8211; Gutenberg Blocks [getwid] < 2.0.5

unknown

[en] The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the recaptcha_api_key_manage function in all versions up to, and including, 2.0.3. This makes it possible for authenticated attackers, with subscriber-level access and above, t...

Affected:
up to 2.0.5
Fixed in:
2.0.5
Disclosed:
Feb 5, 2024

CVE-2023-6959 on NVD →

Getwid &#8211; Gutenberg Blocks [getwid] < 2.0.5

unknown

[en] The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to CAPTCHA Bypass in versions up to, and including, 2.0.4. This makes it possible for unauthenticated attackers to bypass the Captcha Verification of the Contact Form block by omitting 'g-recaptcha-response' from the 'data' array.

Affected:
up to 2.0.5
Fixed in:
2.0.5
Disclosed:
Feb 5, 2024

CVE-2023-6963 on NVD →

Getwid – Gutenberg Blocks <= 2.0.4 - Captcha Bypass

medium

The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to CAPTCHA Bypass in versions up to, and including, 2.0.4. This makes it possible for unauthenticated attackers to bypass the Captcha Verification of the Contact Form block by omitting 'g-recaptcha-response' from the 'data' array.

CVSS:
5.3
Affected:
up to 2.0.4
Fixed in:
2.0.5
Disclosed:
Jan 17, 2024

CVE-2023-6963 on NVD →

Getwid – Gutenberg Blocks <= 2.0.4 - Missing Authorization to Recaptcha API Key Modification

medium

The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the recaptcha_api_key_manage function in all versions up to, and including, 2.0.3. This makes it possible for authenticated attackers, with subscriber-level access and above, to add...

CVSS:
4.3
Affected:
up to 2.0.4
Fixed in:
2.0.5
Disclosed:
Jan 17, 2024

CVE-2023-6959 on NVD →

Getwid &#8211; Gutenberg Blocks [getwid] < 2.0.3

unknown

[en] Any unauthenticated user may send e-mail from the site with any title or content to the admin

Affected:
up to 2.0.3
Fixed in:
2.0.3
Disclosed:
Jan 8, 2024

CVE-2023-6042 on NVD →

Getwid – Gutenberg Blocks <= 2.0.2 - Improper Input Validation to Arbitrary Email Sending to Admin

medium

The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized arbitrary email sending due to insufficient limitations on the content of emails sent in all versions up to, and including, 2.0.2. This makes it possible for unauthenticated attackers to send emails to the site admin with arbitrary content...

CVSS:
5.3
Affected:
up to 2.0.2
Fixed in:
2.0.3
Disclosed:
Dec 15, 2023

CVE-2023-6042 on NVD →

Getwid &#8211; Gutenberg Blocks [getwid] < 1.8.4

unknown

[en] The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to Server Side Request Forgery via the get_remote_content REST API endpoint in versions up to, and including, 1.8.3. This can allow authenticated attackers with subscriber-level permissions or above to make web requests to arbitrary locations origina...

Affected:
up to 1.8.4
Fixed in:
1.8.4
Disclosed:
Jun 9, 2023

CVE-2023-1895 on NVD →

Getwid &#8211; Gutenberg Blocks [getwid] < 1.8.4

unknown

[en] The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized modification of data due to an insufficient capability check on the get_remote_templates function in versions up to, and including, 1.8.3. This makes it possible for authenticated attackers with subscriber-level permissions or above t...

Affected:
up to 1.8.4
Fixed in:
1.8.4
Disclosed:
Jun 9, 2023

CVE-2023-1910 on NVD →

Getwid – Gutenberg Blocks <= 1.8.3 - Authenticated(Subscriber+) Server Side Request Forgery

high

The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to Server Side Request Forgery via the get_remote_content REST API endpoint in versions up to, and including, 1.8.3. This can allow authenticated attackers with subscriber-level permissions or above to make web requests to arbitrary locations originating...

CVSS:
8.5
Affected:
up to 1.8.3
Fixed in:
1.8.4
Disclosed:
Jun 6, 2023

CVE-2023-1895 on NVD →

Getwid – Gutenberg Blocks <= 1.8.3 - Improper Authorization via get_remote_templates REST endpoint

medium

The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized modification of data due to an insufficient capability check on the get_remote_templates function in versions up to, and including, 1.8.3. This makes it possible for authenticated attackers with subscriber-level permissions or above to flu...

CVSS:
4.3
Affected:
up to 1.8.3
Fixed in:
1.8.4
Disclosed:
Jun 6, 2023

CVE-2023-1910 on NVD →

Getwid &#8211; Gutenberg Blocks [getwid] < 1.7.7

unknown

Cross-Site Request Forgery (CSRF) / Settings Change vulnerability discovered in WordPress Getwid – Gutenberg Blocks plugin (versions <= 1.7.4).

Affected:
up to 1.7.7
Fixed in:
1.7.7
Disclosed:
Sep 21, 2021

Getwid &#8211; Gutenberg Blocks [getwid] < 1.7.7

unknown

Authenticated Information Disclosure vulnerability discovered in WordPress Getwid – Gutenberg Blocks plugin (versions <= 1.7.4).

Affected:
up to 1.7.7
Fixed in:
1.7.7
Disclosed:
Sep 21, 2021

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database