plugin

Otter Pro Vulnerabilities

6 known security issues reported for the Otter Pro WordPress plugin. Most recent disclosed Jun 8, 2024.

3 medium

Running Otter Pro on your site? Check whether your installed version is affected.

Scan your site free

Otter Blocks PRO [otter-pro] < 2.6.12

unknown

[en] Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Themeisle Otter Blocks PRO.This issue affects Otter Blocks PRO: from n/a through 2.6.11.

Affected:
up to 2.6.12
Fixed in:
2.6.12
Disclosed:
Jun 8, 2024

CVE-2024-35682 on NVD →

Otter Blocks PRO – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE <= 2.6.11 - Authenticated (Subscriber+) Information Exposure

medium

The Otter Blocks PRO – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.11. This makes it possible for authenticated attackers, with Subscriber-level access and above, to extract sensitive user or con...

CVSS:
4.3
Affected:
up to 2.6.11
Fixed in:
2.6.12
Disclosed:
Jun 6, 2024

CVE-2024-35682 on NVD →

Otter Blocks PRO [otter-pro] < 2.6.4

unknown

[en] The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the contact form file field CSS metabox in all versions up to, and including, 2.6.3 due to insufficient input sanitization and output escaping. This makes it possible f...

Affected:
up to 2.6.4
Fixed in:
2.6.4
Disclosed:
Mar 13, 2024

CVE-2024-1684 on NVD →

Otter Blocks PRO [otter-pro] < 2.6.4

unknown

[en] The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE PRO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via file upload form, which allows SVG uploads, in all versions up to, and including, 2.6.3 due to insufficient input sanitization and output escaping. This makes it po...

Affected:
up to 2.6.4
Fixed in:
2.6.4
Disclosed:
Mar 13, 2024

CVE-2024-1691 on NVD →

Otter Blocks PRO <= 2.6.3 - Authenticated(Contributor+) Stored Cross-Site Scripting via File Field CSS

medium

The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the contact form file field CSS metabox in all versions up to, and including, 2.6.3 due to insufficient input sanitization and output escaping. This makes it possible for au...

CVSS:
6.4
Affected:
up to 2.6.3
Fixed in:
2.6.4
Disclosed:
Mar 6, 2024

CVE-2024-1684 on NVD →

Otter Blocks PRO <= 2.6.3 - Unauthenticated Stored Cross-Site Scripting via SVG Upload

medium

The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE PRO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via file upload form, which allows SVG uploads, in all versions up to, and including, 2.6.3 due to insufficient input sanitization and output escaping. This makes it possibl...

CVSS:
6.1
Affected:
up to 2.6.3
Fixed in:
2.6.4
Disclosed:
Mar 6, 2024

CVE-2024-1691 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database