Vulnerabilities > Themeisle > Otter Blocks

DATE CVE VULNERABILITY TITLE RISK
2024-06-08 CVE-2024-35682 Unspecified vulnerability in Themeisle Otter Blocks
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Themeisle Otter Blocks PRO.This issue affects Otter Blocks PRO: from n/a through 2.6.11.
network
low complexity
themeisle
5.3
2024-05-02 CVE-2024-3725 Cross-site Scripting vulnerability in Themeisle Otter Blocks
The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Post Grid widget in all versions up to, and including, 2.6.9 due to insufficient input sanitization and output escaping on user supplied attributes such as 'titleTag'.
network
low complexity
themeisle CWE-79
5.4
2024-04-11 CVE-2024-3343 Cross-site Scripting vulnerability in Themeisle Otter Blocks
The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's block attributes in all versions up to, and including, 2.6.8 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
themeisle CWE-79
5.4
2024-04-11 CVE-2024-3344 Cross-site Scripting vulnerability in Themeisle Otter Blocks
The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG file upload in all versions up to, and including, 2.6.8 due to insufficient input sanitization and output escaping.
network
low complexity
themeisle CWE-79
5.4
2024-04-09 CVE-2024-2226 Cross-site Scripting vulnerability in Themeisle Otter Blocks
The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the id parameter in the google-map block in all versions up to, and including, 2.6.4 due to insufficient input sanitization and output escaping.
network
low complexity
themeisle CWE-79
5.4
2024-03-29 CVE-2024-2841 Cross-site Scripting vulnerability in Themeisle Otter Blocks
The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets in all versions up to, and including, 2.6.5 due to insufficient input sanitization and output escaping on user supplied attributes such as 'id'.
network
low complexity
themeisle CWE-79
5.4
2024-03-13 CVE-2024-1684 Cross-site Scripting vulnerability in Themeisle Otter Blocks
The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the contact form file field CSS metabox in all versions up to, and including, 2.6.3 due to insufficient input sanitization and output escaping.
network
low complexity
themeisle CWE-79
5.4