← WordPress Vulnerabilities
WordPress security by component

Spectra Legacy – Gutenberg Blocks

Spectra Legacy – Gutenberg Blocks is a WordPress component with 17 published CVE records in this archive. The latest tracked vulnerability was published Jul 20, 2026; the highest CVE/CNA score is 8.8.

Plugin slug: ultimate-addons-for-gutenberg

CVE-2026-12900: Spectra Legacy – Gutenberg Blocks: Cross-site scripting

Spectra Legacy – Gutenberg Blocks is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 2.19.28.

PublishedJul 20, 2026
Known safe version> 2.19.28
Safe version
Jul 20, 2026 CVE-2026-12900
Spectra Legacy – Gutenberg Blocks: Cross-site scripting
Spectra Legacy – Gutenberg Blocks is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 2.19.28.
> 2.19.28
CVE6.4
NVDPending
May 30, 2026 CVE-2026-7465
Spectra Gutenberg Blocks – Website Builder for the Block Editor: Code execution
Spectra Gutenberg Blocks – Website Builder for the Block Editor is affected by code execution. Exploitation requires at least contributor-level access. Successful exploitation can run attacker-controlled code in the WordPress hosting account. The published affected range is <= 2.19.25.
> 2.19.25
CVE8.8
NVDPending
Apr 29, 2026 CVE-2026-42648
Spectra: A security weakness
Spectra is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 2.19.22.
2.19.23
CVE4.3
NVDPending
Feb 03, 2026 CVE-2026-24982
Spectra: A security weakness
Spectra is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Feb 03, 2026 CVE-2026-0950
Spectra Gutenberg Blocks – Website Builder for the Block Editor: Sensitive information exposure
Spectra Gutenberg Blocks – Website Builder for the Block Editor is affected by sensitive information exposure. The vulnerable path is reachable without authentication. Successful exploitation can disclose data that should not be available to the caller.
See mitigation notes
CVE5.3
NVDPending
Dec 09, 2025 CVE-2023-23729
Spectra: A security weakness
Spectra is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.4
NVDPending
Nov 05, 2025 CVE-2025-11162
Spectra Gutenberg Blocks – Website Builder for the Block Editor: Cross-site scripting
Spectra Gutenberg Blocks – Website Builder for the Block Editor is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVDPending
Mar 26, 2025 CVE-2025-1784
Spectra – WordPress Gutenberg Blocks: Cross-site scripting
Spectra – WordPress Gutenberg Blocks is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVDPending
Dec 03, 2024 CVE-2024-10484
Spectra – WordPress Gutenberg Blocks: Cross-site scripting
Spectra – WordPress Gutenberg Blocks is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Nov 01, 2024 CVE-2024-37517
Spectra: A security weakness
Spectra is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVD8.8
Jun 19, 2024 CVE-2023-36676
Spectra: A security weakness
Spectra is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.4
NVD8.8
Jun 03, 2024 CVE-2023-23738
Spectra: A security weakness
Spectra is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVD5.3
Jun 03, 2024 CVE-2023-23735
Spectra: Cross-site scripting
Spectra is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.3
NVD6.1
Jun 03, 2024 CVE-2023-23730
Spectra: A security weakness
Spectra is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVD5.3
May 02, 2024 CVE-2024-3107
Spectra – WordPress Gutenberg Blocks: Filesystem traversal
Spectra – WordPress Gutenberg Blocks is affected by filesystem traversal. Exploitation requires an authenticated WordPress account. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE4.3
NVDPending
Mar 28, 2024 CVE-2023-36679
Spectra: Server-side request forgery
Spectra is affected by server-side request forgery. Exposure depends on how the affected operation is made reachable by the site. The vulnerable server can be induced to make attacker-selected network requests.
See mitigation notes
CVE7.1
NVD6.5
Dec 14, 2023 CVE-2023-49833
Spectra – WordPress Gutenberg Blocks: Cross-site scripting
Spectra – WordPress Gutenberg Blocks is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVD5.4