Spectra Gutenberg Blocks <= 2.19.28 - Authenticated (Contributor+) Stored Cross-Site Scripting via uagb/image Block
medium
The Spectra Gutenberg Blocks – Website Builder for the Block Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `uagb/image` block in all versions up to, and including, 2.19.28 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, w...
- CVSS:
- 6.4
- Affected:
- up to 2.19.28
- Fixed in:
- 2.19.29
- Disclosed:
- Jul 20, 2026
CVE-2026-12900 on NVD →
Spectra Legacy – Gutenberg Blocks < 2.20.0 - Authenticated (Contributor+) CSS Injection
medium
The Spectra Legacy – Gutenberg Blocks plugin for WordPress is vulnerable to CSS Injection in all versions up to 2.20.0 (exclusive). This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary CSS into block attributes.
- CVSS:
- 4.3
- Affected:
- up to 2.20.0
- Fixed in:
- 2.20.0
- Disclosed:
- Jul 20, 2026
CVE-2026-10827 on NVD →
Spectra Gutenberg Blocks <= 2.19.25 - Authenticated (Contributor+) Remote Code Execution via Arbitrary PHP Function Call via Block Attributes
high
The Spectra Gutenberg Blocks – Website Builder for the Block Editor plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.19.25. This makes it possible for authenticated attackers, with Contributor-level access and above, to execute code on the server. Exploitation requires...
- CVSS:
- 8.8
- Affected:
- up to 2.19.25
- Fixed in:
- 2.19.26
- Disclosed:
- May 29, 2026
CVE-2026-7465 on NVD →
Spectra <= 2.19.22 - Missing Authorization
medium
The Spectra plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.19.22. This makes it possible for authenticated attackers, with contributor-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 2.19.22
- Fixed in:
- 2.19.23
- Disclosed:
- Mar 27, 2026
CVE-2026-42648 on NVD →
Spectra Gutenberg Blocks – Website Builder for the Block Editor [ultimate-addons-for-gutenberg] <= 2.19.17 (unfixed)
unknown
[en] Missing Authorization vulnerability in Brainstorm Force Spectra ultimate-addons-for-gutenberg allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Spectra: from n/a through <= 2.19.17.
- Affected:
- up to 2.19.17
- Fix:
- No patched version reported
- Disclosed:
- Feb 3, 2026
CVE-2026-24982 on NVD →
Spectra Gutenberg Blocks <= 2.19.17 - Unauthenticated Information Disclosure in Sensitive Data
medium
The Spectra Gutenberg Blocks – Website Builder for the Block Editor plugin for WordPress is vulnerable to Information Disclosure in all versions up to, and including, 2.19.17. This is due to the plugin failing to check `post_password_required()` before rendering post excerpts in the `render_excerpt()` function and the...
- CVSS:
- 5.3
- Affected:
- up to 2.19.17
- Fixed in:
- 2.19.18
- Disclosed:
- Feb 2, 2026
CVE-2026-0950 on NVD →
Spectra <= 2.19.17 - Missing Authorization
medium
The Spectra Gutenberg Blocks – Website Builder for the Block Editor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.19.17. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 2.19.17
- Fixed in:
- 2.19.18
- Disclosed:
- Jan 17, 2026
CVE-2026-24982 on NVD →
Spectra Gutenberg Blocks – Website Builder for the Block Editor [ultimate-addons-for-gutenberg] < 2.3.2
unknown
[en] Missing Authorization vulnerability in Brainstorm Force Spectra allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Spectra: from n/a through 2.3.0.
- Affected:
- up to 2.3.2
- Fixed in:
- 2.3.2
- Disclosed:
- Dec 9, 2025
CVE-2023-23729 on NVD →
Spectra Gutenberg Blocks – Website Builder for the Block Editor [ultimate-addons-for-gutenberg] < 2.19.15
unknown
[en] The Spectra Gutenberg Blocks – Website Builder for the Block Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custom CSS in all versions up to, and including, 2.19.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with...
- Affected:
- up to 2.19.15
- Fixed in:
- 2.19.15
- Disclosed:
- Nov 5, 2025
CVE-2025-11162 on NVD →
Spectra <= 2.19.14 - Authenticated (Contributor+) Stored Cross-Site Scripting via Custom CSS
medium
The Spectra Gutenberg Blocks – Website Builder for the Block Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custom CSS in all versions up to, and including, 2.19.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Cont...
- CVSS:
- 6.4
- Affected:
- up to 2.19.14
- Fixed in:
- 2.19.15
- Disclosed:
- Nov 4, 2025
CVE-2025-11162 on NVD →
Spectra – WordPress Gutenberg Blocks <= 2.19.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the uagb block in all versions up to, and including, 2.19.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and abo...
- CVSS:
- 6.4
- Affected:
- up to 2.19.0
- Fixed in:
- 2.19.1
- Disclosed:
- Mar 25, 2025
CVE-2025-1784 on NVD →
Spectra Gutenberg Blocks – Website Builder for the Block Editor [ultimate-addons-for-gutenberg] < 2.3.2
unknown
[en] Missing Authorization vulnerability in Brainstorm Force Spectra allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Spectra: from n/a through 2.3.0.
- Affected:
- up to 2.3.2
- Fixed in:
- 2.3.2
- Disclosed:
- Dec 9, 2024
CVE-2023-23825 on NVD →
Spectra Gutenberg Blocks – Website Builder for the Block Editor [ultimate-addons-for-gutenberg] < 2.3.1
unknown
[en] Missing Authorization vulnerability in Brainstorm Force Spectra allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Spectra: from n/a through 2.3.0.
- Affected:
- up to 2.3.1
- Fixed in:
- 2.3.1
- Disclosed:
- Dec 9, 2024
CVE-2023-23834 on NVD →
Spectra Gutenberg Blocks – Website Builder for the Block Editor [ultimate-addons-for-gutenberg] < 2.16.3
unknown
[en] The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'Team' widget in all versions up to, and including, 2.16.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated att...
- Affected:
- up to 2.16.3
- Fixed in:
- 2.16.3
- Disclosed:
- Dec 3, 2024
CVE-2024-10484 on NVD →
Spectra – WordPress Gutenberg Blocks <= 2.16.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Team Widget
medium
The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'Team' widget in all versions up to, and including, 2.16.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attacker...
- CVSS:
- 6.4
- Affected:
- up to 2.16.2
- Fixed in:
- 2.16.3
- Disclosed:
- Dec 2, 2024
CVE-2024-10484 on NVD →
Spectra Gutenberg Blocks – Website Builder for the Block Editor [ultimate-addons-for-gutenberg] < 2.13.8
unknown
[en] Missing Authorization vulnerability in Brainstorm Force Spectra allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Spectra: from n/a through 2.13.7.
- Affected:
- up to 2.13.8
- Fixed in:
- 2.13.8
- Disclosed:
- Nov 1, 2024
CVE-2024-37517 on NVD →
Spectra Gutenberg Blocks – Website Builder for the Block Editor [ultimate-addons-for-gutenberg] < 2.15.1
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Brainstorm Force Spectra allows Stored XSS.This issue affects Spectra: from n/a through 2.14.1.
- Affected:
- up to 2.15.1
- Fixed in:
- 2.15.1
- Disclosed:
- Aug 12, 2024
CVE-2024-7590 on NVD →
Spectra – WordPress Gutenberg Blocks <= 2.15.0 - Authenticated (Contributor+) Stored Cross-site Scripting
medium
The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the FAQ heading tag in all versions up to, and including, 2.15.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, wit...
- CVSS:
- 6.4
- Affected:
- up to 2.15.0
- Fixed in:
- 2.15.1
- Disclosed:
- Aug 7, 2024
CVE-2024-7590 on NVD →
Spectra <= 2.13.7 - Missing Authorization via generate_ai_content
medium
The Spectra plugin for WordPress is vulnerable to unauthorized modification of data due to an insufficient capability check on the generate_ai_content() function in versions up to, and including, 2.13.7. This makes it possible for authenticated attackers, with contributor-level access and above, to generate AI content.
- CVSS:
- 4.3
- Affected:
- up to 2.13.7
- Fixed in:
- 2.13.8
- Disclosed:
- Jul 5, 2024
CVE-2024-37517 on NVD →
Spectra Gutenberg Blocks – Website Builder for the Block Editor [ultimate-addons-for-gutenberg] < 2.6.7
unknown
[en] Missing Authorization vulnerability in Brainstorm Force Spectra.This issue affects Spectra: from n/a through 2.6.6.
- Affected:
- up to 2.6.7
- Fixed in:
- 2.6.7
- Disclosed:
- Jun 19, 2024
CVE-2023-36676 on NVD →
Spectra Gutenberg Blocks – Website Builder for the Block Editor [ultimate-addons-for-gutenberg] < 2.3.2
unknown
[en] Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Brainstorm Force Spectra allows Content Spoofing, Phishing.This issue affects Spectra: from n/a through 2.3.0.
- Affected:
- up to 2.3.2
- Fixed in:
- 2.3.2
- Disclosed:
- Jun 3, 2024
CVE-2023-23738 on NVD →
Spectra Gutenberg Blocks – Website Builder for the Block Editor [ultimate-addons-for-gutenberg] < 2.3.2
unknown
[en] Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Brainstorm Force Spectra allows Code Injection.This issue affects Spectra: from n/a through 2.3.0.
- Affected:
- up to 2.3.2
- Fixed in:
- 2.3.2
- Disclosed:
- Jun 3, 2024
CVE-2023-23735 on NVD →
Spectra Gutenberg Blocks – Website Builder for the Block Editor [ultimate-addons-for-gutenberg] < 2.3.2
unknown
[en] Improper Restriction of Excessive Authentication Attempts vulnerability in Brainstorm Force Spectra allows Functionality Bypass.This issue affects Spectra: from n/a through 2.3.0.
- Affected:
- up to 2.3.2
- Fixed in:
- 2.3.2
- Disclosed:
- Jun 3, 2024
CVE-2023-23730 on NVD →
Spectra Gutenberg Blocks – Website Builder for the Block Editor [ultimate-addons-for-gutenberg] < 2.13.1
unknown
[en] The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘block_id’ parameter in versions up to, and including, 2.13.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level permissi...
- Affected:
- up to 2.13.1
- Fixed in:
- 2.13.1
- Disclosed:
- May 24, 2024
CVE-2024-4366 on NVD →
Spectra – WordPress Gutenberg Blocks <= 2.13.0 - Authenticated (Author+) Stored Cross-Site Scripting
medium
The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘block_id’ parameter in versions up to, and including, 2.13.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level permissions a...
- CVSS:
- 6.4
- Affected:
- up to 2.13.0
- Fixed in:
- 2.13.1
- Disclosed:
- May 23, 2024
CVE-2024-4366 on NVD →
Spectra Gutenberg Blocks – Website Builder for the Block Editor [ultimate-addons-for-gutenberg] < 2.12.9
unknown
[en] The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Testimonial block in all versions up to, and including, 2.12.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated...
- Affected:
- up to 2.12.9
- Fixed in:
- 2.12.9
- Disclosed:
- May 23, 2024
CVE-2024-1814 on NVD →
Spectra Gutenberg Blocks – Website Builder for the Block Editor [ultimate-addons-for-gutenberg] < 2.12.9
unknown
[en] The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Gallery block in all versions up to, and including, 2.12.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticat...
- Affected:
- up to 2.12.9
- Fixed in:
- 2.12.9
- Disclosed:
- May 23, 2024
CVE-2024-1815 on NVD →
Spectra – WordPress Gutenberg Blocks <= 2.12.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image Gallery Block
medium
The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Gallery block in all versions up to, and including, 2.12.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated at...
- CVSS:
- 6.4
- Affected:
- up to 2.12.8
- Fixed in:
- 2.12.9
- Disclosed:
- May 22, 2024
CVE-2024-1815 on NVD →
Spectra – WordPress Gutenberg Blocks <= 2.12.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Testimonial Block
medium
The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Testimonial block in all versions up to, and including, 2.12.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated atta...
- CVSS:
- 6.4
- Affected:
- up to 2.12.8
- Fixed in:
- 2.12.9
- Disclosed:
- May 22, 2024
CVE-2024-1814 on NVD →
Spectra Gutenberg Blocks – Website Builder for the Block Editor [ultimate-addons-for-gutenberg] < 2.12.7
unknown
[en] The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Path Traversal in versions up to, and including, 2.12.6 via the get_block_default_attributes function. This allows authenticated attackers, with contributor-level permissions and above, to read the contents of any files named attributes...
- Affected:
- up to 2.12.7
- Fixed in:
- 2.12.7
- Disclosed:
- May 2, 2024
CVE-2024-3107 on NVD →
Spectra – WordPress Gutenberg Blocks <= 2.12.6 - Authenticated (Contributor+) Path Traversal
medium
The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Path Traversal in versions up to, and including, 2.12.6 via the get_block_default_attributes function. This allows authenticated attackers, with contributor-level permissions and above, to read the contents of any files named attributes.php...
- CVSS:
- 4.3
- Affected:
- up to 2.12.6
- Fixed in:
- 2.12.7
- Disclosed:
- Apr 26, 2024
CVE-2024-3107 on NVD →
Spectra Gutenberg Blocks – Website Builder for the Block Editor [ultimate-addons-for-gutenberg] < 2.10.4
unknown
[en] The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custom CSS metabox in all versions up to and including 2.10.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level acc...
- Affected:
- up to 2.10.4
- Fixed in:
- 2.10.4
- Disclosed:
- Apr 9, 2024
CVE-2023-6486 on NVD →
Spectra – WordPress Gutenberg Blocks <= 2.10.3 - Authenticated(Contributor+) Cross-Site Scripting via Custom CSS
medium
The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custom CSS metabox in all versions up to and including 2.10.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access a...
- CVSS:
- 6.4
- Affected:
- up to 2.10.3
- Fixed in:
- 2.10.4
- Disclosed:
- Apr 3, 2024
CVE-2023-6486 on NVD →
Spectra Gutenberg Blocks – Website Builder for the Block Editor [ultimate-addons-for-gutenberg] < 2.6.7
unknown
[en] Server-Side Request Forgery (SSRF) vulnerability in Brainstorm Force Spectra.This issue affects Spectra: from n/a through 2.6.6.
- Affected:
- up to 2.6.7
- Fixed in:
- 2.6.7
- Disclosed:
- Mar 28, 2024
CVE-2023-36679 on NVD →
Spectra Gutenberg Blocks – Website Builder for the Block Editor [ultimate-addons-for-gutenberg] < 2.7.10
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm Force Spectra – WordPress Gutenberg Blocks allows Stored XSS.This issue affects Spectra – WordPress Gutenberg Blocks: from n/a through 2.7.9.
- Affected:
- up to 2.7.10
- Fixed in:
- 2.7.10
- Disclosed:
- Dec 14, 2023
CVE-2023-49833 on NVD →
Spectra <= 2.7.9 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Spectra plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.7.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that wil...
- CVSS:
- 6.4
- Affected:
- up to 2.7.9
- Fixed in:
- 2.7.10
- Disclosed:
- Dec 5, 2023
CVE-2023-49833 on NVD →
Spectra <= 2.6.6 - Authenticated (Contributor+) Server-Side Request Forgery in import_wpforms
high
The Spectra plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 2.6.6 via the import_wpforms function. This can allow authenticated attackers, with contributor-level permissions and above, to make web requests to arbitrary locations originating from the web application an...
- CVSS:
- 8.5
- Affected:
- up to 2.6.6
- Fixed in:
- 2.6.7
- Disclosed:
- Jul 14, 2023
CVE-2023-36679 on NVD →
Spectra <= 2.6.6 - Authenticated (Contributor+) Server-Side Request Forgery in template_importer
medium
The Spectra plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 2.6.6 via the template_importer function. This can allow authenticated attackers, with contributor-level permissions and above, to make web requests to arbitrary locations originating from the web application...
- CVSS:
- 6.4
- Affected:
- up to 2.6.6
- Fixed in:
- 2.6.7
- Disclosed:
- Jul 14, 2023
Spectra <= 2.6.6 - Missing Authorization
medium
The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.6.6. This makes it possible for authenticated attackers, with Contributor-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 2.6.6
- Fixed in:
- 2.6.7
- Disclosed:
- Jul 14, 2023
CVE-2023-36676 on NVD →
Spectra Gutenberg Blocks – Website Builder for the Block Editor [ultimate-addons-for-gutenberg] < 2.6.7
unknown
The Spectra plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 2.6.6 via the template_importer function. This can allow authenticated attackers, with contributor-level permissions and above, to make web requests to arbitrary locations originating from the web application...
- Affected:
- up to 2.6.7
- Fixed in:
- 2.6.7
- Disclosed:
- Jul 14, 2023
Spectra Gutenberg Blocks – Website Builder for the Block Editor [ultimate-addons-for-gutenberg] < 1.14.8
unknown
[en] The Ultimate Addons for Gutenberg plugin for WordPress is vulnerable to Authenticated Settings Change in versions up to, and including, 1.14.7. This is due to missing capability checks on several AJAX actions. This makes it possible for authenticated attackers with subscriber+ roles to update the plugin's settings...
- Affected:
- up to 1.14.8
- Fixed in:
- 1.14.8
- Disclosed:
- Jun 7, 2023
CVE-2020-36702 on NVD →
Spectra Gutenberg Blocks – Website Builder for the Block Editor [ultimate-addons-for-gutenberg] < 1.15.0
unknown
[en] The Spectra WordPress plugin before 1.15.0 does not sanitize user input as it reaches its style HTML attribute, allowing contributors to conduct stored XSS attacks via the plugin's Gutenberg blocks.
- Affected:
- up to 1.15.0
- Fixed in:
- 1.15.0
- Disclosed:
- Feb 21, 2023
CVE-2020-36656 on NVD →
Spectra – WordPress Gutenberg Blocks <= 2.3.1 - Cross-Site Request Forgery to Plugin Activation
medium
The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.3.1 This is due to missing nonce validation on the activate_plugin function called via an AJAX action. This makes it possible for unauthenticated attackers to activate arbitrary...
- CVSS:
- 6.3
- Affected:
- up to 2.3.1
- Fixed in:
- 2.3.2
- Disclosed:
- Jan 25, 2023
CVE-2023-23834 on NVD →
Spectra – WordPress Gutenberg Blocks <= 2.3.1 - Missing Authorization Checks
medium
The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the import_wpforms, import_block, and activate_plugin functions called via AJAX actions in versions up to, and including, 2.3.1. This makes it possible for authenticated attackers, su...
- CVSS:
- 6.3
- Affected:
- up to 2.3.1
- Fixed in:
- 2.3.2
- Disclosed:
- Jan 25, 2023
Spectra Gutenberg Blocks – Website Builder for the Block Editor [ultimate-addons-for-gutenberg] < 2.3.3
unknown
The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.3.1 This is due to missing nonce validation on the activate_plugin function called via an AJAX action. This makes it possible for unauthenticated attackers to activate arbitrary...
- Affected:
- up to 2.3.3
- Fixed in:
- 2.3.3
- Disclosed:
- Jan 25, 2023
Spectra Gutenberg Blocks – Website Builder for the Block Editor [ultimate-addons-for-gutenberg] < 2.3.2
unknown
The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the import_wpforms, import_block, and activate_plugin functions called via AJAX actions in versions up to, and including, 2.3.1. This makes it possible for authenticated attackers, su...
- Affected:
- up to 2.3.2
- Fixed in:
- 2.3.2
- Disclosed:
- Jan 25, 2023
Spectra – WordPress Gutenberg Blocks <= 1.14.11 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.14.11 due to insufficient sanitizing of input in Gutenberg blocks. This makes it possible for contributors, or higher privileged users, to inject arbitrary web scripts that exec...
- CVSS:
- 6.4
- Affected:
- up to 1.14.11
- Fixed in:
- 1.15.0
- Disclosed:
- Jan 24, 2023
CVE-2020-36656 on NVD →
Spectra – WordPress Gutenberg Blocks <= 2.3.1 - HTML Injection in Emails
medium
The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to HTML injection via Email in versions up to, and including, 2.3.1. This is due to insufficient input validation and output escaping of content being sent via email. This makes it possible for unauthenticated attackers to send emails to unsusp...
- CVSS:
- 6.5
- Affected:
- up to 2.3.1
- Fixed in:
- 2.3.2
- Disclosed:
- Jan 23, 2023
CVE-2023-23735 on NVD →
Spectra – WordPress Gutenberg Blocks <= 2.3.1 - Cross-Site Request Forgery to WPForm/Blocks Import
medium
The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.3.1 This is due to missing nonce validation on the import_wpforms and import_block functions called via AJAX actions. This makes it possible for unauthenticated attackers to impo...
- CVSS:
- 5.4
- Affected:
- up to 2.3.1
- Fixed in:
- 2.3.2
- Disclosed:
- Jan 23, 2023
CVE-2023-23825 on NVD →
Spectra – WordPress Gutenberg Blocks <= 2.3.1 - Missing Authorization to Captcha Setting Update
medium
The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the forms_recaptcha function in versions up to, and including, 2.3.1. This makes it possible for authenticated attackers with contributor-level permissions and above to modify the plu...
- CVSS:
- 5.4
- Affected:
- up to 2.3.1
- Fixed in:
- 2.3.2
- Disclosed:
- Jan 23, 2023
CVE-2023-23729 on NVD →
Spectra – WordPress Gutenberg Blocks <= 2.3.1 - Email Spoofing
medium
The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to email spoofing in versions up to, and including, 2.3.1. This is due to insufficient validation of content being sent to an email. This makes it possible for unauthenticated attackers to send emails to unsuspecting victims with spoofed conten...
- CVSS:
- 5.3
- Affected:
- up to 2.3.1
- Fixed in:
- 2.3.2
- Disclosed:
- Jan 23, 2023
CVE-2023-23738 on NVD →
Spectra – WordPress Gutenberg Blocks <= 2.3.1 - Captcha Bypass
medium
The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to CAPTCHA Bypass in versions up to, and including, 2.3.1. This makes it possible for unauthenticated attackers to bypass the Captcha Verification.
- CVSS:
- 5.3
- Affected:
- up to 2.3.1
- Fixed in:
- 2.3.2
- Disclosed:
- Jan 23, 2023
CVE-2023-23730 on NVD →
Spectra Gutenberg Blocks – Website Builder for the Block Editor [ultimate-addons-for-gutenberg] < 1.25.6
unknown
Reflected Cross-Site Scripting (XSS) vulnerability discovered by WPScanTeam in WordPress Spectra plugin (versions <= 1.25.5).
Update the WordPress Spectra plugin to the latest available version (at least 1.25.6).
- Affected:
- up to 1.25.6
- Fixed in:
- 1.25.6
- Disclosed:
- Jun 13, 2022
Spectra – WordPress Gutenberg Blocks <= 1.25.5 - Reflected Cross-Site Scripting
medium
The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in versions up to, and including, 1.25.5. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages th...
- CVSS:
- 6.1
- Affected:
- up to 1.25.5
- Fixed in:
- 1.25.6
- Disclosed:
- May 31, 2022
Spectra Gutenberg Blocks – Website Builder for the Block Editor [ultimate-addons-for-gutenberg] < 1.25.6
unknown
The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in versions up to, and including, 1.25.5. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages th...
- Affected:
- up to 1.25.6
- Fixed in:
- 1.25.6
- Disclosed:
- May 31, 2022
Spectra Gutenberg Blocks – Website Builder for the Block Editor [ultimate-addons-for-gutenberg] < 1.14.8
unknown
Authenticated Settings Change vulnerability discovered by NinTechNet in WordPress Gutenberg Blocks plugin (versions <= 1.14.7).
- Affected:
- up to 1.14.8
- Fixed in:
- 1.14.8
- Disclosed:
- Apr 8, 2020
Spectra – WordPress Gutenberg Blocks <= 1.14.7 - Missing Authorization
medium
The Ultimate Addons for Gutenberg plugin for WordPress is vulnerable to Authenticated Settings Change in versions up to, and including, 1.14.7. This is due to missing capability checks on several AJAX actions. This makes it possible for authenticated attackers with subscriber+ roles to update the plugin's settings.
- CVSS:
- 5.5
- Affected:
- up to 1.14.7
- Fixed in:
- 1.14.8
- Disclosed:
- Mar 30, 2020
CVE-2020-36702 on NVD →
Spectra Gutenberg Blocks – Website Builder for the Block Editor [ultimate-addons-for-gutenberg] < 2.19.1
unknown
- Affected:
- up to 2.19.1
- Fixed in:
- 2.19.1
CVE-2025-1784 on NVD →
Spectra Gutenberg Blocks – Website Builder for the Block Editor [ultimate-addons-for-gutenberg] < 1.25.6
unknown
The plugin does not escape some URLs before outputting them back in attributes, leading to Reflected Cross-Site Scripting
- Affected:
- up to 1.25.6
- Fixed in:
- 1.25.6
Spectra Gutenberg Blocks – Website Builder for the Block Editor [ultimate-addons-for-gutenberg] < 1.14.8
unknown
The Gutenberg Blocks – Ultimate Addons for Gutenberg WordPress plugin was affected by an Ultimate Addons for Gutenberg < 1.14.8 - Authenticated Settings Change security vulnerability.
- Affected:
- up to 1.14.8
- Fixed in:
- 1.14.8
Spectra Gutenberg Blocks – Website Builder for the Block Editor [ultimate-addons-for-gutenberg] < 1.14.8
unknown
The Ultimate Addons for Gutenberg plugin for WordPress is vulnerable to Authenticated Settings Change in versions up to, and including, 1.14.7. This is due to [state why the vulnerability is created]. This makes it possible for authenticated attackers with Subscriber+ roles to update WordPress settings.
- Affected:
- up to 1.14.8
- Fixed in:
- 1.14.8