Vulnerabilities and security researches formagazine-blocks magazine-blocks
Direction: descendingApr 17, 2026
Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid # CVE-2026-40728
- CVE, Research URL
- Date
- Apr 15, 2026
- Research Description
- Missing Authorization vulnerability in BlockArt Magazine Blocks magazine-blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Magazine Blocks: from n/a through <= 1.8.3.
- Affected versions
-
max 1.8.4.
- Status
-
vulnerable
Jan 03, 2025
Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid # CVE-2024-56258
- CVE, Research URL
- Date
- Jan 02, 2025
- Research Description
- Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPBlockArt Magazine Blocks allows Stored XSS.This issue affects Magazine Blocks: from n/a through 1.3.20.
- Affected versions
-
max 1.3.21.
- Status
-
vulnerable
Oct 27, 2024
Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid # CVE-2024-50429
- CVE, Research URL
- Date
- Oct 29, 2024
- Research Description
- Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPBlockArt Magazine Blocks allows Stored XSS.This issue affects Magazine Blocks: from n/a through 1.3.15.
- Affected versions
-
max 1.3.18.
- Status
-
vulnerable
Oct 03, 2024
Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid # CVE-2024-9218
- CVE, Research URL
- Date
- Oct 02, 2024
- Research Description
- The Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.3.14. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
- Affected versions
-
max 1.3.15.
- Status
-
vulnerable
Jun 07, 2024
Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid # CVE-2024-34760
- CVE, Research URL
- Date
- May 16, 2024
- Research Description
- Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPBlockart Magazine Blocks allows Stored XSS.This issue affects Magazine Blocks: from n/a through 1.3.6.
- Affected versions
-
max 1.3.7.
- Status
-
vulnerable