VendorsThemeisleotter_blocksall versions
Vulnerabilities

Themeisle Otter Blocks

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10CVEs
CVE-2024-11219
Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE <= 3.0.6 - Unauthetnicated Path Traversal to Arbitrary Image View
Published 2024-11-27 · Analyzed
7.5EPSS 0.005
CVE-2024-3725
Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE <= 2.6.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'titleTag'
Published 2024-05-02 · Modified
6.4EPSS 0.004
CVE-2024-1684
Otter Blocks PRO <= 2.6.3 - Authenticated(Contributor+) Stored Cross-Site Scripting via File Field CSS
Published 2024-03-13 · Modified
6.4EPSS 0.004
CVE-2024-2226
Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE <= 2.6.4 - Authenticated (Contributor+) Stored Cross-Site Scripting
Published 2024-04-09 · Modified
6.4EPSS 0.004
CVE-2024-3343
Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE <= 2.6.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Block Attributes
Published 2024-04-11 · Modified
6.4EPSS 0.003
CVE-2024-2841
Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE <= 2.6.5 - Authenticated (Contributor+) Stored Cross-Site Scripting
Published 2024-03-29 · Modified
6.4EPSS 0.003
CVE-2024-3344
Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE <= 2.6.8 - Authenticated (Author+) Limited File Upload to Stored Cross-Site Scripting
Published 2024-04-11 · Modified
6.4EPSS 0.003
CVE-2024-1691
Otter Blocks PRO <= 2.6.3 - Unauthenticated Stored Cross-Site Scripting via SVG Upload
Published 2024-03-13 · Modified
6.1EPSS 0.005
CVE-2024-2729
Otter Blocks < 2.6.6 - Contributor+ Stored XSS
Published 2024-04-18 · Analyzed
6.1EPSS 0.004
CVE-2024-35682
WordPress Otter Blocks PRO plugin <= 2.6.11 - Authenticated Sensitive Data Exposure vulnerability
Published 2024-06-08 · Modified
5.3EPSS 0.003