cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forb-blocks b-blocks

Direction: ascending
Jun 07, 2024

B Blocks – The ultimate block collection # ca74bacceb60973eeb228d127379636c61208cb5

Date
Jul 18, 2023
Research Description
B Blocks &#8211; The ultimate block collection [b-blocks] < 1.7.8 WordPress B Blocks - The ultimate block collection Plugin < 1.7.8 is vulnerable to Cross Site Scripting (XSS) Update the plugin to the latest version. Rafie Muhammad (Patchstack) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress B Blocks - The ultimate block collection Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 1.7.8.
Affected versions
max 1.7.8.
Status
vulnerable
Apr 06, 2025

B Blocks &#8211; The ultimate block collection # CVE-2025-32173

CVE, Research URL

CVE-2025-32173

Date
Apr 04, 2025
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins B Blocks b-blocks allows Stored XSS.This issue affects B Blocks: from n/a through <= 2.0.0.
Affected versions
max 2.0.1.
Status
vulnerable
Aug 12, 2025

B Blocks &#8211; The ultimate block collection # CVE-2025-8059

CVE, Research URL

CVE-2025-8059

Date
Aug 12, 2025
Research Description
The B Blocks plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization and improper input validation within the rgfr_registration() function in all versions up to, and including, 2.0.6. This makes it possible for unauthenticated attackers to create a new account and assign it the administrator role.
Affected versions
max 2.0.7.
Status
vulnerable
Aug 16, 2025

B Blocks &#8211; The ultimate block collection # CVE-2025-54708

CVE, Research URL

CVE-2025-54708

Date
Aug 15, 2025
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins B Blocks b-blocks allows DOM-Based XSS.This issue affects B Blocks: from n/a through <= 2.0.5.
Affected versions
max 2.0.6.
Status
vulnerable
Mar 29, 2026

B Blocks &#8211; The ultimate block collection # CVE-2026-32489

CVE, Research URL

CVE-2026-32489

Date
Mar 25, 2026
Research Description
Missing Authorization vulnerability in bPlugins B Blocks b-blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects B Blocks: from n/a through < 2.0.30.
Affected versions
max 2.0.30.
Status
vulnerable
Apr 23, 2026

B Blocks &#8211; The ultimate block collection # CVE-2026-39579

CVE, Research URL

CVE-2026-39579

Date
-
Research Description
bBlocks – Essential Gutenberg Blocks &amp; Patterns Collection [b-blocks] < 2.0.32 CVE-2026-39579
Affected versions
max 2.0.32.
Status
vulnerable
May 02, 2026

B Blocks &#8211; The ultimate block collection # CVE-2024-13362

CVE, Research URL

CVE-2024-13362

Date
May 01, 2026
Research Description
Multiple plugins and/or themes for WordPress are vulnerable to Reflected Cross-Site Scripting via the url parameter in various versions due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Affected versions
max 2.0.19.
Status
vulnerable
Oct 07, 2026

B Blocks &#8211; The ultimate block collection # CVE-2026-104400

CVE, Research URL

CVE-2026-104400

Date
Oct 05, 2026
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins B Blocks b-blocks allows Stored XSS.This issue affects B Blocks: from n/a through 2.1.8.
Affected versions
max 2.1.9.
Status
vulnerable