Essential Blocks
Vendor:
First CVE: Jun 9, 2023 · Active for 3 years
25
Total CVEs
More Total CVEs than 95% of tracked products
8.3
Avg CVEs / Year
Higher CVE frequency than 94% of tracked products
6.3
Avg CVSS
Higher Avg CVSS than 27% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Essential Blocks over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 9, 2023
3 years ago
Most Recent CVE
Mar 8, 2025
503 days ago
CVE Severity & Scoring
Essential Blocks25 CVEs
68%
24%
All CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network25 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low24 (96.0%)
High1 (4.0%)
Unknown0 (0.0%)
User Interaction
None13 (52.0%)
Unknown0 (0.0%)
Required12 (48.0%)
Privileges Required
Low19 (76.0%)
High1 (4.0%)
None5 (20.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (25 CVEs).
25 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-6623CRITICAL The Essential Blocks WordPress plugin before 4.4.3 does not prevent unauthenticated attackers from overwriting local variables when rendering templates over the REST API, which may | Jan 15, 2024 | 9.8 | 68 | NO | YES |
CVE-2023-4402CRITICAL The Essential Blocks plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.2.0 via deserialization of untrusted input in the get_products f | Oct 20, 2023 | 9.8 | 30 | NO | NO |
CVE-2023-51360HIGH Missing Authorization vulnerability in WPDeveloper Essential Blocks for Gutenberg essential-blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issu | Dec 9, 2024 | 8.8 | 24 | NO | NO |
CVE-2023-51359HIGH Missing Authorization vulnerability in WPDeveloper Essential Blocks for Gutenberg essential-blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issu | Dec 9, 2024 | 8.8 | 24 | NO | NO |
CVE-2025-26871HIGH Missing Authorization vulnerability in WPDeveloper Essential Blocks for Gutenberg essential-blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issu | Feb 25, 2025 | 8.8 | 23 | NO | NO |
CVE-2023-4386HIGH The Essential Blocks plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.2.0 via deserialization of untrusted input in the get_posts func | Oct 20, 2023 | 8.1 | 23 | NO | NO |
CVE-2023-47760HIGH Missing Authorization vulnerability in WPDeveloper Essential Blocks for Gutenberg essential-blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issu | Dec 9, 2024 | 8.8 | 22 | NO | NO |
CVE-2024-30467HIGH Missing Authorization vulnerability in WPDeveloper Essential Blocks for Gutenberg.This issue affects Essential Blocks for Gutenberg: from n/a through 4.4.9. | Jun 9, 2024 | 8.8 | 22 | NO | NO |
CVE-2022-47594MEDIUM Missing Authorization vulnerability in WPDeveloper Essential Blocks for Gutenberg allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Essenti | Dec 13, 2024 | 6.5 | 20 | NO | NO |
CVE-2025-1664MEDIUM The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Parallax slider in all versions | Mar 8, 2025 | 5.4 | 18 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (25 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
4.0% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (25 CVEs).
Media Mentions
Signals from CVEs in this product scope (25 CVEs).
Top CNAs Publishing CVEs For Essential Blocks
Top CWEs
Versions
No cataloged versions.