📦 Ultimate Blocks

by Dotcamp

🔍 What is Ultimate Blocks?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-2918

MEDIUM CVSS 6.4 Jun 10, 2025

This stored XSS vulnerability in the Ultimate Blocks WordPress plugin allows authenticated attackers with Contributor-level access or higher to inject malicious scripts into website pages. These scrip...

CVE-2024-10678

MEDIUM CVSS 5.4 Dec 13, 2024

The Ultimate Blocks WordPress plugin before version 3.2.4 contains a stored cross-site scripting (XSS) vulnerability. Users with contributor role or higher can inject malicious scripts into posts/page...

CVE-2024-6362

MEDIUM CVSS 4.6 Jul 29, 2024

The Ultimate Blocks WordPress plugin before version 3.2.0 has a stored cross-site scripting (XSS) vulnerability in its post-grid block. Users with contributor role or higher can inject malicious scrip...

CVE-2024-37457

MEDIUM CVSS 6.5 Jul 21, 2024

This vulnerability allows attackers to inject malicious scripts into web pages generated by the Ultimate Blocks WordPress plugin, which are then executed when other users view those pages. It affects ...

CVE-2024-4655

MEDIUM CVSS 5.4 Jul 11, 2024

The Ultimate Blocks WordPress plugin before version 3.1.9 has a stored cross-site scripting (XSS) vulnerability. Users with contributor role or higher can inject malicious scripts into posts/pages, wh...

CVE-2024-4268

MEDIUM CVSS 6.4 Jul 2, 2024

This vulnerability allows authenticated WordPress users with contributor-level access or higher to inject malicious scripts into website pages using the Ultimate Blocks plugin. The scripts execute whe...

CVE-2024-3513

MEDIUM CVSS 6.4 Jul 2, 2024

This vulnerability allows authenticated WordPress users with contributor-level access or higher to inject malicious scripts into website pages via the Ultimate Blocks plugin's title tag parameter. The...