← WordPress Vulnerabilities
WordPress security by component

Spectra

Spectra is a WordPress component with 10 published CVE records in this archive. The latest tracked vulnerability was published Dec 09, 2024; the highest CVE/CNA score is 6.5.

Plugin slug: spectra

CVE-2023-23834: Spectra: A security weakness

Spectra is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.

PublishedDec 09, 2024
Safe version guidanceSee mitigation notes
Safe version
Dec 09, 2024 CVE-2023-23834
Spectra: A security weakness
Spectra is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVD9.8
Dec 09, 2024 CVE-2023-23825
Spectra: A security weakness
Spectra is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE3.1
NVD8.8
Aug 12, 2024 CVE-2024-7590
Spectra: Cross-site scripting
Spectra is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVD5.4
Aug 02, 2024 CVE-2024-3827
Spectra Pro: Cross-site scripting
Spectra Pro is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
May 24, 2024 CVE-2024-4366
Spectra – WordPress Gutenberg Blocks: Cross-site scripting
Spectra – WordPress Gutenberg Blocks is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
May 23, 2024 CVE-2024-1815
Spectra – WordPress Gutenberg Blocks: Cross-site scripting
Spectra – WordPress Gutenberg Blocks is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
May 23, 2024 CVE-2024-1814
Spectra – WordPress Gutenberg Blocks: Cross-site scripting
Spectra – WordPress Gutenberg Blocks is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Apr 09, 2024 CVE-2023-6486
Spectra – WordPress Gutenberg Blocks: Cross-site scripting
Spectra – WordPress Gutenberg Blocks is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Jun 07, 2023 CVE-2020-36702
Ultimate Addons for Gutenberg: A security weakness
Ultimate Addons for Gutenberg is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.5
NVD4.3
Feb 21, 2023 CVE-2020-36656
Spectra: Cross-site scripting
Spectra is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVD5.4