Otter Blocks PRO [otter-pro] < 2.6.12
unknown
[en] Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Themeisle Otter Blocks PRO.This issue affects Otter Blocks PRO: from n/a through 2.6.11.
- Affected:
- up to 2.6.12
- Fixed in:
- 2.6.12
- Disclosed:
- Jun 8, 2024
CVE-2024-35682 on NVD →
Otter Blocks PRO – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE <= 2.6.11 - Authenticated (Subscriber+) Information Exposure
medium
The Otter Blocks PRO – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.11. This makes it possible for authenticated attackers, with Subscriber-level access and above, to extract sensitive user or con...
- CVSS:
- 4.3
- Affected:
- up to 2.6.11
- Fixed in:
- 2.6.12
- Disclosed:
- Jun 6, 2024
CVE-2024-35682 on NVD →
Otter Blocks PRO [otter-pro] < 2.6.4
unknown
[en] The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the contact form file field CSS metabox in all versions up to, and including, 2.6.3 due to insufficient input sanitization and output escaping. This makes it possible f...
- Affected:
- up to 2.6.4
- Fixed in:
- 2.6.4
- Disclosed:
- Mar 13, 2024
CVE-2024-1684 on NVD →
Otter Blocks PRO [otter-pro] < 2.6.4
unknown
[en] The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE PRO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via file upload form, which allows SVG uploads, in all versions up to, and including, 2.6.3 due to insufficient input sanitization and output escaping. This makes it po...
- Affected:
- up to 2.6.4
- Fixed in:
- 2.6.4
- Disclosed:
- Mar 13, 2024
CVE-2024-1691 on NVD →
Otter Blocks PRO <= 2.6.3 - Authenticated(Contributor+) Stored Cross-Site Scripting via File Field CSS
medium
The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the contact form file field CSS metabox in all versions up to, and including, 2.6.3 due to insufficient input sanitization and output escaping. This makes it possible for au...
- CVSS:
- 6.4
- Affected:
- up to 2.6.3
- Fixed in:
- 2.6.4
- Disclosed:
- Mar 6, 2024
CVE-2024-1684 on NVD →
Otter Blocks PRO <= 2.6.3 - Unauthenticated Stored Cross-Site Scripting via SVG Upload
medium
The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE PRO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via file upload form, which allows SVG uploads, in all versions up to, and including, 2.6.3 due to insufficient input sanitization and output escaping. This makes it possibl...
- CVSS:
- 6.1
- Affected:
- up to 2.6.3
- Fixed in:
- 2.6.4
- Disclosed:
- Mar 6, 2024
CVE-2024-1691 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database