Vulnerabilities and security researches formagazine-blocks magazine-blocks
Direction: ascendingJun 07, 2024
Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid # CVE-2024-34760
- CVE, Research URL
- Date
- May 16, 2024
- Research Description
- Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPBlockart Magazine Blocks allows Stored XSS.This issue affects Magazine Blocks: from n/a through 1.3.6.
- Affected versions
-
max 1.3.7.
- Status
-
vulnerable
Oct 03, 2024
Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid # CVE-2024-9218
- CVE, Research URL
- Date
- Oct 02, 2024
- Research Description
- The Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.3.14. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
- Affected versions
-
max 1.3.15.
- Status
-
vulnerable
Oct 27, 2024
Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid # CVE-2024-50429
- CVE, Research URL
- Date
- Oct 29, 2024
- Research Description
- Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BlockArt Magazine Blocks magazine-blocks allows DOM-Based XSS.This issue affects Magazine Blocks: from n/a through <= 1.3.15.
- Affected versions
-
max 1.3.18.
- Status
-
vulnerable
Jan 03, 2025
Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid # CVE-2024-56258
- CVE, Research URL
- Date
- Jan 02, 2025
- Research Description
- Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BlockArt Magazine Blocks magazine-blocks allows Stored XSS.This issue affects Magazine Blocks: from n/a through <= 1.3.20.
- Affected versions
-
max 1.3.21.
- Status
-
vulnerable
Apr 17, 2026
Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid # CVE-2026-40728
- CVE, Research URL
- Date
- Apr 15, 2026
- Research Description
- Missing Authorization vulnerability in BlockArt Magazine Blocks magazine-blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Magazine Blocks: from n/a through <= 1.8.3.
- Affected versions
-
max 1.8.4.
- Status
-
vulnerable
Jul 01, 2026
Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid # CVE-2026-57650
- CVE, Research URL
- Date
- Jun 26, 2026
- Research Description
- Contributor Cross Site Scripting (XSS) in Magazine Blocks <= 1.8.3 versions.
- Affected versions
-
max 1.8.4.
- Status
-
vulnerable
Aug 26, 2026
Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid # CVE-2026-78290
- CVE, Research URL
- Date
- Aug 24, 2026
- Research Description
- Contributor Cross Site Scripting (XSS) in Magazine Blocks <= 1.8.6 versions.
- Affected versions
-
max 1.8.7.
- Status
-
vulnerable
Sep 19, 2026
Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid # CVE-2026-75017
- CVE, Research URL
- Date
- Sep 18, 2026
- Research Description
- The Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.8.6. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with contributor-level access and above, to demote administrator-owned published builder templates (header, footer, front page, single, archive, 404, and search) to draft status and replace them with attacker-authored block content rendered site-wide, enabling defacement, phishing, and SEO spam. This is possible because the mzb-builder-template post type is registered with capability_type='post' and exposed via the REST API, and the _mzb_template meta key is accessible to any user with edit_posts capability, meaning Contributor-level users and above can trigger the vulnerable save_post() hook.
- Affected versions
-
max 1.8.7.
- Status
-
vulnerable
Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid # CVE-2026-75016
- CVE, Research URL
- Date
- Sep 18, 2026
- Research Description
- The Magazine Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the News Ticker block's clientId attribute in versions up to, and including, 1.8.6. This is due to insufficient input sanitization and output escaping in the NewsTicker::render() method, which concatenates the clientId block attribute into an HTML class attribute without applying esc_attr(). This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
- Affected versions
-
max 1.8.7.
- Status
-
vulnerable