Medium 6.5
2025-09-22< 2.3.13
ZoloBlocks <= 2.3.12 - Authenticated (Contributor+) Stored Cross-Site Scripting
Minimum safe version
2.3.13
Update to 2.3.13 or later to address 6 fixable vulnerabilities
ZoloBlocks <= 2.3.12 - Authenticated (Contributor+) Stored Cross-Site Scripting
CVE-2025-12134
ZoloBlocks <= 2.3.11 - Missing Authorization
CVE-2025-60161
ZoloBlocks – Gutenberg Block Editor Plugin with Advanced Blocks, Dynamic Content, Templates & Patterns <= 2.3.10 - Authenticated (Contributor+) Stored Cross-Site Scripting
CVE-2025-53210