Vulnerabilities > Themeisle > Otter Blocks > 2.6.9

DATE CVE VULNERABILITY TITLE RISK
2024-06-08 CVE-2024-35682 Unspecified vulnerability in Themeisle Otter Blocks
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Themeisle Otter Blocks PRO.This issue affects Otter Blocks PRO: from n/a through 2.6.11.
network
low complexity
themeisle
5.3
2024-05-02 CVE-2024-3725 Cross-site Scripting vulnerability in Themeisle Otter Blocks
The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Post Grid widget in all versions up to, and including, 2.6.9 due to insufficient input sanitization and output escaping on user supplied attributes such as 'titleTag'.
network
low complexity
themeisle CWE-79
5.4