Vulnerabilities > Wpdeveloper > Essential Blocks > 4.2.5

DATE CVE VULNERABILITY TITLE RISK
2024-01-15 CVE-2023-6623 Path Traversal vulnerability in Wpdeveloper Essential Blocks
The Essential Blocks WordPress plugin before 4.4.3 does not prevent unauthenticated attackers from overwriting local variables when rendering templates over the REST API, which may lead to Local File Inclusion attacks.
network
low complexity
wpdeveloper CWE-22
critical
9.8
2024-01-11 CVE-2023-7071 Cross-site Scripting vulnerability in Wpdeveloper Essential Blocks
The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Table of Contents block in all versions up to, and including, 4.4.6 due to insufficient input sanitization and output escaping.
network
low complexity
wpdeveloper CWE-79
5.4