Blocksera develops WordPress plugins and web-application extensions, including cryptocurrency widgets and image-hover components, that introduce input-handling and access-control vulnerabilities into websites that deploy them. The vulnerability profile centers on application-layer weaknesses such as SQL injection, cross-site scripting, improper access control, and missing authentication for critical functions—issues endemic to web-application plugins where sanitization and privilege boundaries are often overlooked. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Blocksera over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-36888CRITICAL Unauthenticated Arbitrary Options Update vulnerability leading to full website compromise discovered in Image Hover Effects Ultimate (versions <= 9.6.1) WordPress plugin. | Dec 15, 2021 | 9.8 | 46 | NO | YES |
CVE-2022-4059CRITICAL The Cryptocurrency Widgets Pack WordPress plugin before 2.0 does not sanitise and escape some parameter before using it in a SQL statement via an AJAX action available to unauthent | Jan 2, 2023 | 9.8 | 44 | NO | YES |
CVE-2022-44588CRITICAL Unauth. SQL Injection vulnerability in Cryptocurrency Widgets Pack Plugin <=1.8.1 on WordPress. | Dec 15, 2022 | 9.8 | 44 | NO | YES |
CVE-2021-24264MEDIUM The “Image Hover Effects – Elementor Addon” WordPress Plugin before 1.3.4 has a widget that is vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as con | May 5, 2021 | 5.4 | 20 | NO | NO |
CVE-2025-31539MEDIUM Missing Authorization vulnerability in Blocksera Cryptocurrency Widgets Pack cryptocurrency-widgets-pack allows Exploiting Incorrectly Configured Access Control Security Levels.Thi | Mar 31, 2025 | 6.5 | 17 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Blocksera.
Media articles that mention a CVE ID that affects a product developed by Blocksera — matched by CVE ID, not by vendor name.