plugin

Wp Blockade Vulnerabilities

2 known security issues reported for the Wp Blockade WordPress plugin. Most recent disclosed May 21, 2026.

2 medium

Running Wp Blockade on your site? Check whether your installed version is affected.

Scan your site free

WP Blockade <= 0.9.14 - Reflected Cross-Site Scripting via 'shortcode' Parameter

medium

The WP Blockade plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'shortcode' parameter in all versions up to and including 0.9.14. This is due to insufficient input sanitization and output escaping in the render_shortcode_preview() function. The function receives user input from $_GET['short...

CVSS:
6.1
Affected:
up to 0.9.14
Fix:
No patched version reported
Disclosed:
May 21, 2026

CVE-2026-3481 on NVD →

WP Blockade <= 0.9.14 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Shortcode Execution via 'shortcode' Parameter

medium

The WP Blockade plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 0.9.14. The plugin registers an admin_post action hook 'wp-blockade-shortcode-render' that maps to the render_shortcode_preview() function. This function lacks any capability check (current_user_can()) and no...

CVSS:
6.5
Affected:
up to 0.9.14
Fix:
No patched version reported
Disclosed:
Apr 7, 2026

CVE-2026-3480 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database