Getwid
Vendor:
First CVE: Jun 9, 2023 · Active for 3 years
10
Total CVEs
More Total CVEs than 89% of tracked products
5.0
Avg CVEs / Year
Higher CVE frequency than 89% of tracked products
5.7
Avg CVSS
Higher Avg CVSS than 20% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Getwid over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 9, 2023
3 years ago
Most Recent CVE
Nov 20, 2024
615 days ago
CVE Severity & Scoring
Getwid10 CVEs
80%
10%
10%
All CVEs353,173 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network10 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None7 (70.0%)
Unknown0 (0.0%)
Required3 (30.0%)
Privileges Required
Low7 (70.0%)
High0 (0.0%)
None3 (30.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-1895CRITICAL The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to Server Side Request Forgery via the get_remote_content REST API endpoint in versions up to, and including, 1.8.3 | Jun 9, 2023 | 9.6 | 27 | NO | NO |
CVE-2023-6042HIGH Any unauthenticated user may send e-mail from the site with any title or content to the admin | Jan 8, 2024 | 7.5 | 23 | NO | NO |
CVE-2024-3588MEDIUM The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Countdown block in all versions up to, and including, 2.0.7 due to | May 2, 2024 | 5.4 | 17 | NO | NO |
CVE-2023-6963MEDIUM The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to CAPTCHA Bypass in versions up to, and including, 2.0.4. This makes it possible for unauthenticated attackers to | Feb 5, 2024 | 5.3 | 17 | NO | NO |
CVE-2023-1910MEDIUM The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized modification of data due to an insufficient capability check on the get_remote_templates function i | Jun 9, 2023 | 4.3 | 17 | NO | NO |
CVE-2024-10872MEDIUM The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `template-post-custom-field` block in all versions up to, and including, 2.0 | Nov 20, 2024 | 5.4 | 16 | NO | NO |
CVE-2024-6489MEDIUM The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the get_google_api_key function in all ve | Jul 20, 2024 | 5.3 | 16 | NO | NO |
CVE-2024-6491MEDIUM The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the mailchimp_api_key_manage function in | Jul 20, 2024 | 4.3 | 15 | NO | NO |
CVE-2024-1948MEDIUM The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the block content in all versions up to, and including, 2.0.5 due to insufficien | Apr 9, 2024 | 5.4 | 15 | NO | NO |
CVE-2023-6959MEDIUM The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the recaptcha_api_key_manage function in | Feb 5, 2024 | 4.3 | 15 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (10 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (10 CVEs).
Media Mentions
Signals from CVEs in this product scope (10 CVEs).
Top CNAs Publishing CVEs For Getwid
Top CWEs
Versions
No cataloged versions.