Vulnerabilities and security researches forb-blocks b-blocks
Direction: ascendingJun 07, 2024
B Blocks – The ultimate block collection # ca74bacceb60973eeb228d127379636c61208cb5
- CVE, Research URL
- Application
- Date
- Jul 18, 2023
- Research Description
- B Blocks – The ultimate block collection [b-blocks] < 1.7.8 WordPress B Blocks - The ultimate block collection Plugin < 1.7.8 is vulnerable to Cross Site Scripting (XSS) Update the plugin to the latest version. Rafie Muhammad (Patchstack) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress B Blocks - The ultimate block collection Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 1.7.8.
- Affected versions
-
max 1.7.8.
- Status
-
vulnerable
Apr 06, 2025
B Blocks – The ultimate block collection # CVE-2025-32173
- CVE, Research URL
- Application
- Date
- Apr 04, 2025
- Research Description
- Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins B Blocks b-blocks allows Stored XSS.This issue affects B Blocks: from n/a through <= 2.0.0.
- Affected versions
-
max 2.0.1.
- Status
-
vulnerable
Aug 12, 2025
B Blocks – The ultimate block collection # CVE-2025-8059
- CVE, Research URL
- Application
- Date
- Aug 12, 2025
- Research Description
- The B Blocks plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization and improper input validation within the rgfr_registration() function in all versions up to, and including, 2.0.6. This makes it possible for unauthenticated attackers to create a new account and assign it the administrator role.
- Affected versions
-
max 2.0.7.
- Status
-
vulnerable
Aug 16, 2025
B Blocks – The ultimate block collection # CVE-2025-54708
- CVE, Research URL
- Application
- Date
- Aug 15, 2025
- Research Description
- Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins B Blocks b-blocks allows DOM-Based XSS.This issue affects B Blocks: from n/a through <= 2.0.5.
- Affected versions
-
max 2.0.6.
- Status
-
vulnerable
Mar 29, 2026
B Blocks – The ultimate block collection # CVE-2026-32489
- CVE, Research URL
- Application
- Date
- Mar 25, 2026
- Research Description
- Missing Authorization vulnerability in bPlugins B Blocks b-blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects B Blocks: from n/a through < 2.0.30.
- Affected versions
-
max 2.0.30.
- Status
-
vulnerable
Apr 23, 2026
B Blocks – The ultimate block collection # CVE-2026-39579
- CVE, Research URL
- Application
- Date
- -
- Research Description
- bBlocks – Essential Gutenberg Blocks & Patterns Collection [b-blocks] < 2.0.32 CVE-2026-39579
- Affected versions
-
max 2.0.32.
- Status
-
vulnerable
May 02, 2026
B Blocks – The ultimate block collection # CVE-2024-13362
- CVE, Research URL
- Application
- Date
- May 01, 2026
- Research Description
- Multiple plugins and/or themes for WordPress are vulnerable to Reflected Cross-Site Scripting via the url parameter in various versions due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
- Affected versions
-
max 2.0.19.
- Status
-
vulnerable
Oct 07, 2026
B Blocks – The ultimate block collection # CVE-2026-104400
- CVE, Research URL
- Application
- Date
- Oct 05, 2026
- Research Description
- Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins B Blocks b-blocks allows Stored XSS.This issue affects B Blocks: from n/a through 2.1.8.
- Affected versions
-
max 2.1.9.
- Status
-
vulnerable