plugin

Vk Blocks Vulnerabilities

12 known security issues reported for the Vk Blocks WordPress plugin. Most recent disclosed Mar 7, 2025.

6 medium

Running Vk Blocks on your site? Check whether your installed version is affected.

Scan your site free

VK Blocks [vk-blocks] < 1.95.0.3

unknown

[en] The VK Blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.94.2.2 via the page content block. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive data including the content of private posts...

Affected:
up to 1.95.0.3
Fixed in:
1.95.0.3
Disclosed:
Mar 7, 2025

CVE-2024-13635 on NVD →

VK Blocks <= 1.94.2.2 - Missing Authorization to Sensitive Information Exposure

medium

The VK Blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.94.2.2 via the page content block. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive data including the content of private posts and...

CVSS:
4.3
Affected:
up to 1.94.2.2
Fixed in:
1.95.0.3
Disclosed:
Mar 6, 2025

CVE-2024-13635 on NVD →

VK Blocks [vk-blocks] < 1.64.0.0

unknown

[en] The VK Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'vk-blocks/ancestor-page-list' block in all versions up to, and including, 1.63.0.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attac...

Affected:
up to 1.64.0.0
Fixed in:
1.64.0.0
Disclosed:
Nov 22, 2023

CVE-2023-5706 on NVD →

VK Blocks <= 1.63.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Block

medium

The VK Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'vk-blocks/ancestor-page-list' block in all versions up to, and including, 1.63.0.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers...

CVSS:
6.4
Affected:
up to 1.63.0.1
Fixed in:
1.64.0.0
Disclosed:
Oct 24, 2023

CVE-2023-5706 on NVD →

VK Blocks [vk-blocks] < 1.57.1.2

unknown

[en] The VK Blocks plugin for WordPress is vulnerable to improper authorization via the REST 'update_vk_blocks_options' function in versions up to, and including, 1.57.0.5. This allows authenticated attackers, with contributor-level permissions or above, to change plugin settings including default icons.

Affected:
up to 1.57.1.2
Fixed in:
1.57.1.2
Disclosed:
Jun 3, 2023

CVE-2023-0583 on NVD →

VK Blocks [vk-blocks] < 1.58.0.0

unknown

[en] The VK Blocks plugin for WordPress is vulnerable to improper authorization via the REST 'update_options' function in versions up to, and including, 1.57.0.5. This allows authenticated attackers, with contributor-level permissions or above, to change the 'vk_font_awesome_version' option to an arbitrary value.

Affected:
up to 1.58.0.0
Fixed in:
1.58.0.0
Disclosed:
Jun 3, 2023

CVE-2023-0584 on NVD →

VK Blocks <= 1.57.0.5 - Authenticated(Contributor+) Settings Update

medium

The VK Blocks plugin for WordPress is vulnerable to improper authorization via the REST 'update_vk_blocks_options' function in versions up to, and including, 1.57.0.5. This allows authenticated attackers, with contributor-level permissions or above, to change plugin settings including default icons.

CVSS:
4.3
Affected:
up to 1.57.0.5
Fixed in:
1.57.0.10
Disclosed:
Jun 2, 2023

CVE-2023-0583 on NVD →

VK Blocks <= 1.57.0.5 - Authenticated(Contributor+) Settings Update

medium

The VK Blocks plugin for WordPress is vulnerable to improper authorization via the REST 'update_options' function in versions up to, and including, 1.57.0.5. This allows authenticated attackers, with contributor-level permissions or above, to change the 'vk_font_awesome_version' option to an arbitrary value.

CVSS:
4.3
Affected:
up to 1.57.0.5
Fixed in:
1.58.0.0
Disclosed:
Jun 2, 2023

CVE-2023-0584 on NVD →

VK Blocks [vk-blocks] < 1.54.0.0

unknown

[en] Cross-site scripting vulnerability in Tag edit function of VK Blocks 1.53.0.1 and earlier and VK Blocks Pro 1.53.0.1 and earlier allows a remote authenticated attacker to inject an arbitrary script.

Affected:
up to 1.54.0.0
Fixed in:
1.54.0.0
Disclosed:
May 23, 2023

CVE-2023-27923 on NVD →

VK Blocks [vk-blocks] < 1.54.0.0

unknown

[en] Cross-site scripting vulnerability in Post function of VK Blocks 1.53.0.1 and earlier and VK Blocks Pro 1.53.0.1 and earlier allows a remote authenticated attacker to inject an arbitrary script.

Affected:
up to 1.54.0.0
Fixed in:
1.54.0.0
Disclosed:
May 23, 2023

CVE-2023-27925 on NVD →

VK Blocks <= 1.53.0.1 - Stored (Contributor+) Cross-Site Scripting in Post

medium

The VK Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Post functionality in versions up to, and including, 1.53.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject ar...

CVSS:
6.4
Affected:
up to 1.53.0.1
Fixed in:
1.54.0
Disclosed:
May 9, 2023

CVE-2023-27925 on NVD →

VK Blocks <= 1.53.0.1 - Stored (Contributor+) Cross-Site Scripting in Tag Edit

medium

The VK Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Tag Edit functionality in versions up to, and including, 1.53.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to injec...

CVSS:
6.4
Affected:
up to 1.53.0.1
Fixed in:
1.54.0
Disclosed:
May 9, 2023

CVE-2023-27923 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database