Dotcamp maintains a small portfolio of WordPress plugins, including Ultimate Blocks and WP Table Builder, that extend content creation and data presentation capabilities within WordPress sites. The recurring vulnerability signal centers on cross-site scripting (XSS) weaknesses in user-input handling and content generation, a pattern typical of web-facing plugins where output sanitization is critical to preventing client-side injection. Current severity, exploitation status, and exposure metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Dotcamp over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-10678MEDIUM The Ultimate Blocks WordPress plugin before 3.2.4 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which | Dec 13, 2024 | 5.4 | 19 | NO | NO |
CVE-2024-43125MEDIUM Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WP Table Builder WP Table Builder – WordPress Table Plugin allows Store | Aug 12, 2024 | 6.5 | 19 | NO | NO |
CVE-2022-46852MEDIUM Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WP Table Builder plugin <= 1.4.6 versions. | May 3, 2023 | 4.8 | 19 | NO | NO |
CVE-2024-6362MEDIUM The Ultimate Blocks WordPress plugin before 3.2.0 does not validate and escape some of its post-grid block attributes before outputting them back in a page/post where the block is | Jul 29, 2024 | 4.6 | 18 | NO | NO |
CVE-2024-4655MEDIUM The Ultimate Blocks WordPress plugin before 3.1.9 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which | Jul 11, 2024 | 5.4 | 18 | NO | NO |
CVE-2025-2918MEDIUM The Ultimate Blocks – WordPress Blocks Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 3.3.3 due | Jun 10, 2025 | 5.4 | 17 | NO | NO |
CVE-2024-8536MEDIUM The Ultimate Blocks WordPress plugin before 3.2.2 does not validate and escape some of its block attributes before outputting them back in a page/post where the block is embed, wh | Sep 30, 2024 | 5.4 | 17 | NO | NO |
CVE-2024-37457MEDIUM Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Ultimate Blocks Ultimate Blocks – Gutenberg Blocks Plugin allows Stored | Jul 21, 2024 | 5.4 | 17 | NO | NO |
CVE-2024-4268MEDIUM The Ultimate Blocks – WordPress Blocks Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's blocks in all versions up to, and including, 3.1.9 | Jul 2, 2024 | 5.4 | 17 | NO | NO |
CVE-2024-3513MEDIUM The Ultimate Blocks – WordPress Blocks Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the title tag (postTitleTag) parameter in all versions up to, an | Jul 2, 2024 | 5.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Dotcamp.
Media articles that mention a CVE ID that affects a product developed by Dotcamp — matched by CVE ID, not by vendor name.