plugin

Responsive Block Editor Addons Vulnerabilities

17 known security issues reported for the Responsive Block Editor Addons WordPress plugin. Most recent disclosed Apr 20, 2026.

10 medium

Running Responsive Block Editor Addons on your site? Check whether your installed version is affected.

Scan your site free

Responsive Blocks <= 2.2.1 - Missing Authorization to Authenticated (Contributor+) Arbitrary Modification via AJAX Actions

medium

The Responsive Blocks – Page Builder for Blocks & Patterns plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 2.2.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with cont...

CVSS:
4.3
Affected:
2.0.9 – 2.2.1
Fixed in:
2.2.2
Disclosed:
Apr 20, 2026

CVE-2026-6703 on NVD →

Responsive Blocks <= 2.2.0 - Unauthenticated Open Email Relay via REST API 'email_to' Parameter

medium

The Responsive Blocks – Page Builder for Blocks & Patterns plugin for WordPress is vulnerable to Unauthenticated Open Email Relay in all versions up to, and including, 2.2.0. This is due to insufficient authorization checks and missing server-side validation of the recipient email address supplied via a public REST API...

CVSS:
5.3
Affected:
up to 2.2.0
Fixed in:
2.2.1
Disclosed:
Apr 20, 2026

CVE-2026-6675 on NVD →

Responsive Blocks – Page Builder for Blocks & Patterns <= 2.2.0 - Missing Authorization

medium

The Responsive Blocks – Page Builder for Blocks & Patterns plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.2.0. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 2.2.0
Fixed in:
2.2.1
Disclosed:
Mar 11, 2026

CVE-2026-32543 on NVD →

Responsive Blocks <= 2.0.6 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Responsive Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.0.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in page...

CVSS:
6.4
Affected:
up to 2.0.6
Fixed in:
2.0.7
Disclosed:
Jun 27, 2025

CVE-2025-53202 on NVD →

Responsive Blocks &#8211; WordPress Gutenberg Blocks [responsive-block-editor-addons] < 2.0.7

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CyberChimps Responsive Blocks allows DOM-Based XSS. This issue affects Responsive Blocks: from n/a through 2.0.6.

Affected:
up to 2.0.7
Fixed in:
2.0.7
Disclosed:
Jun 27, 2025

CVE-2025-53202 on NVD →

Responsive Blocks &#8211; WordPress Gutenberg Blocks [responsive-block-editor-addons] < 2.0.6

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CyberChimps Responsive Blocks allows Stored XSS. This issue affects Responsive Blocks: from n/a through 2.0.5.

Affected:
up to 2.0.6
Fixed in:
2.0.6
Disclosed:
Jun 17, 2025

CVE-2025-49881 on NVD →

Responsive Blocks <= 2.0.5 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Responsive Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.0.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in page...

CVSS:
6.4
Affected:
up to 2.0.5
Fixed in:
2.0.6
Disclosed:
Jun 12, 2025

CVE-2025-49881 on NVD →

Responsive Blocks <= 2.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Responsive Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in page...

CVSS:
6.4
Affected:
up to 2.0.2
Fixed in:
2.0.3
Disclosed:
Apr 16, 2025

CVE-2025-39578 on NVD →

Responsive Blocks &#8211; WordPress Gutenberg Blocks [responsive-block-editor-addons] < 2.0.3

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CyberChimps Responsive Blocks allows Stored XSS. This issue affects Responsive Blocks: from n/a through 2.0.2.

Affected:
up to 2.0.3
Fixed in:
2.0.3
Disclosed:
Apr 16, 2025

CVE-2025-39578 on NVD →

Responsive Blocks &#8211; WordPress Gutenberg Blocks [responsive-block-editor-addons] < 2.0.0

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CyberChimps Responsive Blocks allows Reflected XSS. This issue affects Responsive Blocks: from n/a through 1.9.9.

Affected:
up to 2.0.0
Fixed in:
2.0.0
Disclosed:
Feb 4, 2025

CVE-2025-22697 on NVD →

Responsive Blocks <= 1.9.9 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Responsive Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.9.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in page...

CVSS:
6.4
Affected:
up to 1.9.9
Fixed in:
2.0.0
Disclosed:
Jan 31, 2025

CVE-2025-22697 on NVD →

Responsive Blocks &#8211; WordPress Gutenberg Blocks [responsive-block-editor-addons] < 2.0.0

unknown

[en] The Responsive Blocks – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘section_tag’ parameter in all versions up to, and including, 1.9.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contr...

Affected:
up to 2.0.0
Fixed in:
2.0.0
Disclosed:
Jan 30, 2025

CVE-2024-13732 on NVD →

Responsive Blocks – WordPress Gutenberg Blocks <= 1.9.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via section_tag Parameter

medium

The Responsive Blocks – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘section_tag’ parameter in all versions up to, and including, 1.9.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributo...

CVSS:
6.4
Affected:
up to 1.9.9
Fixed in:
2.0.0
Disclosed:
Jan 29, 2025

CVE-2024-13732 on NVD →

Responsive Blocks &#8211; WordPress Gutenberg Blocks [responsive-block-editor-addons] < 1.9.8

unknown

[en] The Responsive Blocks – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'responsive-block-editor-addons/portfolio' block in all versions up to, and including, 1.9.7 due to insufficient input sanitization and output escaping. This makes it possible for authentica...

Affected:
up to 1.9.8
Fixed in:
1.9.8
Disclosed:
Dec 24, 2024

CVE-2024-12268 on NVD →

Responsive Blocks – WordPress Gutenberg Blocks <= 1.9.7 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Responsive Blocks – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'responsive-block-editor-addons/portfolio' block in all versions up to, and including, 1.9.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated a...

CVSS:
6.4
Affected:
up to 1.9.7
Fixed in:
1.9.8
Disclosed:
Dec 23, 2024

CVE-2024-12268 on NVD →

Responsive Blocks &#8211; WordPress Gutenberg Blocks [responsive-block-editor-addons] < 1.8.9

unknown

[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CyberChimps Responsive Blocks – WordPress Gutenberg Blocks allows Stored XSS.This issue affects Responsive Blocks – WordPress Gutenberg Blocks: from n/a through 1.8.8.

Affected:
up to 1.8.9
Fixed in:
1.8.9
Disclosed:
Aug 18, 2024

CVE-2024-43335 on NVD →

Responsive Blocks – WordPress Gutenberg Blocks <= 1.8.8 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Responsive Blocks – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the taxonomy block in versions up to, and including, 1.8.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level acces...

CVSS:
6.4
Affected:
up to 1.8.8
Fixed in:
1.8.9
Disclosed:
Aug 16, 2024

CVE-2024-43335 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database