Otter Blocks
Vendor:
First CVE: Mar 13, 2024 · Active for 2 years
10
Total CVEs
More Total CVEs than 88% of tracked products
10.0
Avg CVEs / Year
Higher CVE frequency than 96% of tracked products
5.7
Avg CVSS
Higher Avg CVSS than 17% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Otter Blocks over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 13, 2024
2 years ago
Most Recent CVE
Nov 27, 2024
604 days ago
CVE Severity & Scoring
Otter Blocks10 CVEs
90%
10%
All CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network10 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None2 (20.0%)
Unknown0 (0.0%)
Required8 (80.0%)
Privileges Required
Low6 (60.0%)
High0 (0.0%)
None4 (40.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-11219HIGH The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 3.0.6 via th | Nov 27, 2024 | 7.5 | 20 | NO | NO |
CVE-2024-2729MEDIUM The Otter Blocks WordPress plugin before 2.6.6 does not properly escape its mainHeadings blocks' attribute before appending it to the final rendered block, allowing contributors t | Apr 18, 2024 | 6.1 | 19 | NO | NO |
CVE-2024-3343MEDIUM The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's block attributes in | Apr 11, 2024 | 5.4 | 18 | NO | NO |
CVE-2024-1691MEDIUM The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE PRO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via file upload form, which allow | Mar 13, 2024 | 6.1 | 18 | NO | NO |
CVE-2024-1684MEDIUM The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the contact form file field CSS m | Mar 13, 2024 | 5.4 | 18 | NO | NO |
CVE-2024-35682MEDIUM Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Themeisle Otter Blocks PRO.This issue affects Otter Blocks PRO: from n/a through 2.6.11. | Jun 8, 2024 | 5.3 | 17 | NO | NO |
CVE-2024-3344MEDIUM The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG file upload in all versions u | Apr 11, 2024 | 5.4 | 17 | NO | NO |
CVE-2024-3725MEDIUM The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Post Grid widget in | May 2, 2024 | 5.4 | 16 | NO | NO |
CVE-2024-2226MEDIUM The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the id parameter in the google-ma | Apr 9, 2024 | 5.4 | 16 | NO | NO |
CVE-2024-2841MEDIUM The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets in all versi | Mar 29, 2024 | 5.4 | 15 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (10 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (10 CVEs).
Media Mentions
Signals from CVEs in this product scope (10 CVEs).
Top CNAs Publishing CVEs For Otter Blocks
Top CWEs
Versions
No cataloged versions.