plugin

The Plus Addons For Block Editor Vulnerabilities

14 known security issues reported for the The Plus Addons For Block Editor WordPress plugin. Most recent disclosed Aug 3, 2026.

14 medium

Running The Plus Addons For Block Editor on your site? Check whether your installed version is affected.

Scan your site free

Nexter Blocks <= 5.0.1 - Authenticated (Author+) Stored Cross-Site Scripting

medium

The Nexter Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that wi...

CVSS:
6.4
Affected:
up to 5.0.1
Fixed in:
5.0.2
Disclosed:
Aug 3, 2026

CVE-2025-15678 on NVD →

Nexter Blocks <= 5.0.1 - Payment Bypass to Authenticated (Contributor+) Stored CSS Injection

medium

The Nexter Blocks plugin for WordPress is vulnerable to Payment Bypass in versions up to, and including, 5.0.1. This is due to a lack of server-side payment verification. This makes it possible for authenticated attackers, with contributor-level access and above, to bypass payments.

CVSS:
4.3
Affected:
up to 5.0.1
Fixed in:
5.0.2
Disclosed:
Aug 3, 2026

CVE-2026-17011 on NVD →

Nexter Blocks <= 5.0.0 - Authenticated (Subscriber+) Path Traversal to Arbitrary CSS/JS File Deletion via 'plus_name' Parameter

medium

The Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 5.0.0 via the 'plus_name' parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary JS/...

CVSS:
4.3
Affected:
up to 5.0.0
Fixed in:
5.0.1
Disclosed:
Jul 23, 2026

CVE-2026-15420 on NVD →

Nexter Blocks <= 4.7.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'commentIcon' Block Attribute

medium

The Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'commentIcon' parameter in all versions up to, and including, 4.7.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attac...

CVSS:
6.4
Affected:
up to 4.7.4
Fixed in:
4.7.5
Disclosed:
Jul 7, 2026

CVE-2026-6740 on NVD →

Nexter Blocks <= 4.7.0 - Unauthenticated Information Exposure

medium

The Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.7.0. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.

CVSS:
5.3
Affected:
up to 4.7.0
Fixed in:
4.7.1
Disclosed:
Mar 26, 2026

CVE-2026-39516 on NVD →

Nexter Blocks <= 4.6.3 - Authenticated (Subscriber+) Information Exposure

medium

The Nexter Gutenberg Blocks – Website Builder & 1000+ Starter Templates plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.6.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to extract sensitive user or configuration...

CVSS:
4.3
Affected:
up to 4.6.3
Fixed in:
4.6.4
Disclosed:
Jan 26, 2026

CVE-2026-24377 on NVD →

Nexter Blocks <= 4.5.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets

medium

The Nexter Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 4.5.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access a...

CVSS:
6.4
Affected:
up to 4.5.4
Fixed in:
4.5.5
Disclosed:
Aug 18, 2025

CVE-2025-8567 on NVD →

Nexter Blocks <= 4.5.4 - Missing Authorization

medium

The Nexter Blocks – WordPress Gutenberg Blocks & 1000+ Starter Templates plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 4.5.4. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 4.5.4
Fixed in:
4.5.5
Disclosed:
Aug 14, 2025

CVE-2025-54739 on NVD →

Nexter Blocks <= 4.0.7 - Missing Authorization

medium

The Nexter Blocks – WordPress Gutenberg Blocks & 1000+ Starter Templates plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 4.0.7. This makes it possible for authenticated attackers, with Contributor-level access and above, to...

CVSS:
4.3
Affected:
up to 4.0.7
Fixed in:
4.0.8
Disclosed:
Jan 3, 2025

CVE-2024-56294 on NVD →

Nexter Blocks <= 4.0.4 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Nexter Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.0.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages th...

CVSS:
6.4
Affected:
up to 4.0.4
Fixed in:
4.0.5
Disclosed:
Dec 30, 2024

CVE-2024-56246 on NVD →

Multiple Plugins <= (Various Versions) - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via FancyBox JavaScript Library

medium

Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled FancyBox JavaScript library (versions 1.3.4 to 3.5.7) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with...

CVSS:
6.4
Affected:
up to 4.3.1
Fixed in:
4.3.2
Disclosed:
Dec 3, 2024

CVE-2024-5020 on NVD →

Nexter Blocks <= 3.3.3 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Nexter Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.3.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages th...

CVSS:
6.4
Affected:
up to 3.3.3
Fixed in:
4.0.0
Disclosed:
Oct 24, 2024

CVE-2024-50452 on NVD →

The Plus Blocks for Block Editor | Gutenberg <= 3.2.5 - Missing Authorization

medium

The The Plus Blocks for Block Editor | Gutenberg plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the Tp_f_delete_transient() function in versions up to, and including, 3.2.5. This makes it possible for authenticated attackers, with subscriber-level access and above,...

CVSS:
4.3
Affected:
up to 3.2.5
Fixed in:
3.2.6
Disclosed:
Apr 25, 2024

CVE-2024-33572 on NVD →

The Plus Blocks for Block Editor | Gutenberg <= 3.2.5 - Reflected Cross-Site Scripting

medium

The The Plus Blocks for Block Editor | Gutenberg plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.2.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that exe...

CVSS:
6.1
Affected:
up to 3.2.5
Fixed in:
3.2.6
Disclosed:
Mar 28, 2024

CVE-2024-30435 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database