CVE-2026-42648
Spectra Gutenberg Blocks – Website Builder for the Block Editor
Minimum safe version
2.19.23
Update to 2.19.23 or later to address 33 fixable vulnerabilities
Spectra Gutenberg Blocks <= 2.19.17 - Unauthenticated Information Disclosure in Sensitive Data
CVE-2026-24982
CVE-2025-11162
Spectra – WordPress Gutenberg Blocks <= 2.19.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
CVE-2024-10484
CVE-2024-7590
CVE-2024-37517
CVE-2024-4366
CVE-2024-1814
CVE-2024-1815
CVE-2024-3107
CVE-2023-6486
CVE-2023-49833
Spectra <= 2.6.6 - Authenticated (Contributor+) Server-Side Request Forgery in template_importer
CVE-2023-36679
CVE-2023-36676
CVE-2020-36702
CVE-2020-36656
CVE-2023-23834
CVE-2023-23825
CVE-2023-23730
CVE-2023-23735
CVE-2023-23738
CVE-2023-23729
Spectra – WordPress Gutenberg Blocks <= 2.3.1 - Missing Authorization Checks
Spectra – WordPress Gutenberg Blocks <= 2.3.1 - Cross-Site Request Forgery to Plugin Activation
Spectra – WordPress Gutenberg Blocks <= 1.14.7 - Authenticated Settings Change
Spectra – WordPress Gutenberg Blocks <= 1.25.5 - Reflected Cross-Site Scripting
Gutenberg Blocks - Ultimate Addons for Gutenberg < 1.14.8 - Authenticated Settings Change
Spectra < 1.25.6 - Reflected Cross-Site Scripting
WordPress Spectra plugin <= 1.25.5 - Reflected Cross-Site Scripting (XSS) vulnerability
WordPress Gutenberg Blocks plugin <= 1.14.7 - Authenticated Settings Change vulnerability