CVE-2025-49929
Ultimate Blocks – 25+ Gutenberg Blocks for Block Editor
Minimum safe version
3.3.7
Update to 3.3.7 or later to address 21 fixable vulnerabilities
Ultimate Blocks – WordPress Blocks Plugin <= 3.3.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets
CVE-2025-48234
CVE-2025-47493
CVE-2025-31077
Ultimate Blocks <= 3.2.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via content Parameter
Ultimate Blocks – WordPress Blocks Plugin <= 3.2.7 - Authenticated (Contributor+) Stored Cross-Site Scripting
CVE-2024-10678
Freemius SDK <= 2.4.2 - Missing Authorization Checks
CVE-2024-8536
CVE-2024-6362
CVE-2024-37457
CVE-2024-4268
CVE-2024-3513
CVE-2024-4655
CVE-2023-6692
WordPress Ultimate Blocks – Gutenberg Blocks Plugin Plugin < 3.1.7 is vulnerable to Cross Site Scripting (XSS)
WordPress Ultimate Blocks – Gutenberg Blocks Plugin Plugin <= 3.0.0 is vulnerable to Cross Site Scripting (XSS)
Freemius SDK <= 2.4.2 - Missing Authorization Checks
WordPress Ultimate Blocks – Gutenberg Blocks Plugin plugin < 2.4.13 - Sensitive Information Disclosure vulnerability
WordPress Ultimate Blocks – Gutenberg Blocks Plugin plugin < 2.4.13 - Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability