Otter Blocks <= 3.1.4 - Improper Authorization to Unauthenticated Purchase Verification Bypass via Forged Cookie
high
The Otter Blocks plugin for WordPress is vulnerable to Purchase Verification Bypass in all versions up to, and including, 3.1.4. This is due to the 'get_customer_data' method relying on an unsigned 'o_stripe_data' cookie to determine Stripe product ownership for unauthenticated users. The 'check_purchase' method trusts...
- CVSS:
- 7.5
- Affected:
- up to 3.1.4
- Fixed in:
- 3.1.5
- Disclosed:
- Apr 29, 2026
CVE-2026-2892 on NVD →
Otter - Gutenberg Block <= 3.1.0 - Unauthenticated Sensitive Information Exposure
medium
The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.1.0. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.
- CVSS:
- 5.3
- Affected:
- up to 3.1.0
- Fixed in:
- 3.1.1
- Disclosed:
- Aug 27, 2025
CVE-2025-55715 on NVD →
Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE [otter-blocks] < 3.1.1 (closed)
unknown
[en] Insertion of Sensitive Information Into Sent Data vulnerability in Themeisle Otter - Gutenberg Block allows Retrieve Embedded Sensitive Data. This issue affects Otter - Gutenberg Block: from n/a through 3.1.0.
- Affected:
- up to 3.1.1
- Fixed in:
- 3.1.1
- Disclosed:
- Aug 20, 2025
CVE-2025-55715 on NVD →
Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE [otter-blocks] < 3.0.7 (closed)
unknown
[en] The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 3.0.6 via the get_image function. This makes it possible for unauthenticated attackers to view arbitrary images on the server, which can contain se...
- Affected:
- up to 3.0.7
- Fixed in:
- 3.0.7
- Disclosed:
- Nov 27, 2024
CVE-2024-11219 on NVD →
Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE <= 3.0.6 - Unauthetnicated Path Traversal to Arbitrary Image View
medium
The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 3.0.6 via the get_image function. This makes it possible for unauthenticated attackers to view arbitrary images on the server, which can contain sensiti...
- CVSS:
- 5.3
- Affected:
- up to 3.0.6
- Fixed in:
- 3.0.7
- Disclosed:
- Nov 26, 2024
CVE-2024-11219 on NVD →
Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE [otter-blocks] < 3.0.4 (closed)
unknown
[en] Missing Authorization vulnerability in ThemeIsle Otter - Gutenberg Block allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Otter - Gutenberg Block: from n/a through 3.0.3.
- Affected:
- up to 3.0.4
- Fixed in:
- 3.0.4
- Disclosed:
- Nov 19, 2024
CVE-2024-51671 on NVD →
Otter - Gutenberg Block <= 3.0.3 - Missing Authorization
medium
The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.0.3. This makes it possible for authenticated attackers, with Author-level access and above, to p...
- CVSS:
- 4.3
- Affected:
- up to 3.0.3
- Fixed in:
- 3.0.4
- Disclosed:
- Nov 1, 2024
CVE-2024-51671 on NVD →
Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE [otter-blocks] < 3.0.5 (closed)
unknown
[en] The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API SVG File uploads in all versions up to, and including, 3.0.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticat...
- Affected:
- up to 3.0.5
- Fixed in:
- 3.0.5
- Disclosed:
- Nov 1, 2024
CVE-2024-10367 on NVD →
Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE <= 3.0.4 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload
medium
The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API SVG File uploads in all versions up to, and including, 3.0.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated at...
- CVSS:
- 6.4
- Affected:
- up to 3.0.4
- Fixed in:
- 3.0.5
- Disclosed:
- Oct 31, 2024
CVE-2024-10367 on NVD →
Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE [otter-blocks] < 2.6.10 (closed)
unknown
[en] The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Post Grid widget in all versions up to, and including, 2.6.9 due to insufficient input sanitization and output escaping on user supplied attributes such as...
- Affected:
- up to 2.6.10
- Fixed in:
- 2.6.10
- Disclosed:
- May 2, 2024
CVE-2024-3725 on NVD →
Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE [otter-blocks] < 2.6.6 (closed)
unknown
[en] The Otter Blocks WordPress plugin before 2.6.6 does not properly escape its mainHeadings blocks' attribute before appending it to the final rendered block, allowing contributors to conduct Stored XSS attacks.
- Affected:
- up to 2.6.6
- Fixed in:
- 2.6.6
- Disclosed:
- Apr 18, 2024
CVE-2024-2729 on NVD →
Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE <= 2.6.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'titleTag'
medium
The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Post Grid widget in all versions up to, and including, 2.6.9 due to insufficient input sanitization and output escaping on user supplied attributes such as 'tit...
- CVSS:
- 6.4
- Affected:
- up to 2.6.9
- Fixed in:
- 2.6.10
- Disclosed:
- Apr 16, 2024
CVE-2024-3725 on NVD →
Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE [otter-blocks] < 2.6.9 (closed)
unknown
[en] The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's block attributes in all versions up to, and including, 2.6.8 due to insufficient input sanitization and output escaping on user supplied attributes. This m...
- Affected:
- up to 2.6.9
- Fixed in:
- 2.6.9
- Disclosed:
- Apr 11, 2024
CVE-2024-3343 on NVD →
Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE [otter-blocks] < 2.6.9 (closed)
unknown
[en] The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG file upload in all versions up to, and including, 2.6.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attacke...
- Affected:
- up to 2.6.9
- Fixed in:
- 2.6.9
- Disclosed:
- Apr 11, 2024
CVE-2024-3344 on NVD →
Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE <= 2.6.8 - Authenticated (Author+) Limited File Upload to Stored Cross-Site Scripting
medium
The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG file upload in all versions up to, and including, 2.6.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, w...
- CVSS:
- 6.4
- Affected:
- up to 2.6.8
- Fixed in:
- 2.6.9
- Disclosed:
- Apr 10, 2024
CVE-2024-3344 on NVD →
Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE <= 2.6.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Block Attributes
medium
The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's block attributes in all versions up to, and including, 2.6.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes...
- CVSS:
- 6.4
- Affected:
- up to 2.6.8
- Fixed in:
- 2.6.9
- Disclosed:
- Apr 10, 2024
CVE-2024-3343 on NVD →
Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE [otter-blocks] < 2.6.5 (closed)
unknown
[en] The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the id parameter in the google-map block in all versions up to, and including, 2.6.4 due to insufficient input sanitization and output escaping. This makes it possible...
- Affected:
- up to 2.6.5
- Fixed in:
- 2.6.5
- Disclosed:
- Apr 9, 2024
CVE-2024-2226 on NVD →
Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE [otter-blocks] < 2.6.6 (closed)
unknown
[en] The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets in all versions up to, and including, 2.6.5 due to insufficient input sanitization and output escaping on user supplied attributes such as 'id'. Th...
- Affected:
- up to 2.6.6
- Fixed in:
- 2.6.6
- Disclosed:
- Mar 29, 2024
CVE-2024-2841 on NVD →
Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE <= 2.6.5 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets in all versions up to, and including, 2.6.5 due to insufficient input sanitization and output escaping on user supplied attributes such as 'id'. This ma...
- CVSS:
- 6.4
- Affected:
- up to 2.6.5
- Fixed in:
- 2.6.6
- Disclosed:
- Mar 28, 2024
CVE-2024-2841 on NVD →
Otter Blocks <= 2.6.5 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via new post creation in all versions up to, and including, 2.6.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,...
- CVSS:
- 6.4
- Affected:
- up to 2.6.5
- Fixed in:
- 2.6.6
- Disclosed:
- Mar 28, 2024
CVE-2024-2729 on NVD →
Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE <= 2.6.4 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the id parameter in the google-map block in all versions up to, and including, 2.6.4 due to insufficient input sanitization and output escaping. This makes it possible for a...
- CVSS:
- 6.4
- Affected:
- up to 2.6.4
- Fixed in:
- 2.6.5
- Disclosed:
- Mar 13, 2024
CVE-2024-2226 on NVD →
ThemeIsle SDK <= Various Versions - Missing Authorization
medium
Multiple plugins and/or themes for WordPress with the ThemeIsle SDK are vulnerable to unauthorized modification of data due to a missing capability check on the register_reference() function in various versions. This makes it possible for unauthenticated attackers to update options values that allow ThemeIsle to track...
- CVSS:
- 5.3
- Affected:
- up to 2.6.2
- Fixed in:
- 2.6.3
- Disclosed:
- Feb 1, 2024
CVE-2024-1047 on NVD →
Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE [otter-blocks] < 2.2.6 (closed)
unknown
[en] The Otter WordPress plugin before 2.2.6 does not sanitize some user-controlled file paths before performing file operations on them. This leads to a PHAR deserialization vulnerability on PHP < 8.0 using the phar:// stream wrapper.
- Affected:
- up to 2.2.6
- Fixed in:
- 2.2.6
- Disclosed:
- May 30, 2023
CVE-2023-2288 on NVD →
Otter - Gutenberg Blocks <= 2.2.5 - Authenticated (Author+) PHAR Deserialization
high
The Otter - Gutenberg Blocks plugin for WordPress is vulnerable to deserialization of untrusted input via the 'fallback' parameter in versions up to, and including 1.2.7. This makes it possible for authenticated attackers with author privileges to call files using a PHAR wrapper that will deserialize and call arbitrary...
- CVSS:
- 8.8
- Affected:
- up to 2.2.5
- Fixed in:
- 2.2.6
- Disclosed:
- May 2, 2023
CVE-2023-2288 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database