← WordPress Vulnerabilities
WordPress security by component

Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE

Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE is a WordPress component with 13 published CVE records in this archive. The latest tracked vulnerability was published Apr 30, 2026; the highest CVE/CNA score is 7.5.

Plugin slug: otter-blocks

CVE-2026-2892: Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE: A security weakness

Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 3.1.4.

PublishedApr 30, 2026
Known safe version> 3.1.4
Safe version
Apr 30, 2026 CVE-2026-2892
Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE: A security weakness
Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 3.1.4.
> 3.1.4
CVE7.5
NVDPending
Aug 20, 2025 CVE-2025-55715
Otter - Gutenberg Block: A security weakness
Otter - Gutenberg Block is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.5
NVDPending
Nov 27, 2024 CVE-2024-11219
Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE: Filesystem traversal
Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE is affected by filesystem traversal. The vulnerable path is reachable without authentication. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE5.3
NVD7.5
Nov 19, 2024 CVE-2024-51671
Otter - Gutenberg Block: A security weakness
Otter - Gutenberg Block is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE2.7
NVDPending
Nov 01, 2024 CVE-2024-10367
Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE: Cross-site scripting
Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE is affected by cross-site scripting. Exploitation requires at least author-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVDPending
May 02, 2024 CVE-2024-3725
Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE: Cross-site scripting
Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Apr 18, 2024 CVE-2024-2729
Otter Blocks: Cross-site scripting
Otter Blocks is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVDPending
Apr 11, 2024 CVE-2024-3344
Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE: Cross-site scripting
Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE is affected by cross-site scripting. Exploitation requires at least author-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Apr 11, 2024 CVE-2024-3343
Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE: Cross-site scripting
Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Apr 09, 2024 CVE-2024-2226
Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE: Cross-site scripting
Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Mar 29, 2024 CVE-2024-2841
Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE: Cross-site scripting
Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Mar 13, 2024 CVE-2024-1691
Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE PRO: Cross-site scripting
Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE PRO is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVDPending
Mar 13, 2024 CVE-2024-1684
Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE: Cross-site scripting
Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4