plugin

Thim Blocks Vulnerabilities

1 known security issue reported for the Thim Blocks WordPress plugin. Most recent disclosed Jan 16, 2026.

1 medium

Running Thim Blocks on your site? Check whether your installed version is affected.

Scan your site free

Gutenberg Thim Blocks <= 1.0.1 - Authenticated (Contributor+) Arbitrary File Read via 'iconSVG' Parameter

medium

The Gutenberg Thim Blocks – Page Builder, Gutenberg Blocks for the Block Editor plugin for WordPress is vulnerable to arbitrary file reads in all versions up to, and including, 1.0.1. This is due to insufficient path validation in the server-side rendering of the thim-blocks/icon block. This makes it possible for authe...

CVSS:
6.5
Affected:
up to 1.0.1
Fixed in:
1.0.2
Disclosed:
Jan 16, 2026

CVE-2025-13725 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database