Cross-Site Scripting
15 records48.4%First: 2024. Latest: 2026.
Plugin security history
The Wordfence Intelligence dataset currently contains 31 vulnerability records associated with Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns, published between 2023 and 2026.
Dataset last synchronized: 2026-08-03 00:31:25 UTC
At a glance
| Year | Records | Relative volume |
|---|---|---|
| 2023 | 11 | |
| 2024 | 9 | |
| 2025 | 8 | |
| 2026 | 3 |
| Severity | Records | Share |
|---|---|---|
| Critical | 1 | 3.2% |
| High | 3 | 9.7% |
| Medium | 27 | 87.1% |
First: 2024. Latest: 2026.
First: 2023. Latest: 2025.
First: 2023. Latest: 2026.
First: 2023. Latest: 2023.
First: 2023. Latest: 2023.
Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.
6.2.06.1.46.1.05.7.35.7.25.4.15.3.25.3.04.8.45.1.14.9.04.7.04.5.134.5.104.5.44.4.104.5.24.4.74.4.34.2.14.0.73.8.6Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.
| Affected range | Vulnerability | Published | Patched version | Severity |
|---|---|---|---|---|
*-6.1.4 | Gutenberg Essential Blocks - Page Builder for Gutenberg Blocks & Patterns <= 6.1.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'configurablePrefix' Block Attribute | June 24, 2026 | 6.2.0 | Medium |
*-6.1.3 | Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns <= 6.1.3 - Authenticated (Author+) Server-Side Request Forgery | June 4, 2026 | 6.1.4 | High |
*-6.0.4 | Gutenberg Essential Blocks <= 6.0.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Block Attributes | May 1, 2026 | 6.1.0 | Medium |
*-5.7.2 | Essential Blocks <= 5.7.2 - Missing Authorization To Authenticated (Author+) Information Disclosure | December 16, 2025 | 5.7.3 | Medium |
*-5.7.1 | Essential Blocks <= 5.7.1 - Authenticated (Author+) Server-Side Request Forgery | October 17, 2025 | 5.7.2 | Medium |
*-5.7.1 | Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns <= 5.7.1 - Authenticated (Contributor+) Stored Cross-Site Scripting | October 17, 2025 | 5.7.2 | Medium |
*-5.4.0 | Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates <= 5.4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Slider and Post Carousel Widgets | May 26, 2025 | 5.4.1 | Medium |
*-5.3.1 | Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates <= 5.3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting | March 7, 2025 | 5.3.2 | Medium |
*-5.2.3 | Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates <= 5.2.3 - Authenticated (Contributor+) Stored Cross-Site Scripting | February 25, 2025 | 5.3.0 | Medium |
*-4.8.3 | Essential Blocks for Gutenberg <= 4.8.3 - Missing Authorization | February 22, 2025 | 4.8.4 | Medium |
*-5.1.0 | Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates <= 5.0.9 - Authenticated (Admin+) Stored Cross-Site Scripting | January 7, 2025 | 5.1.1 | Medium |
*-4.8.4 | Essential Blocks for Gutenberg <= 4.8.4 - Authenticated (Contributor+) Stored Cross-Site Scripting | September 30, 2024 | 4.9.0 | Medium |
*-4.6.1 | Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates <= 4.6.1 - Authenticated (Contributor+) Stored Cross-Site Scripting | July 12, 2024 | 4.7.0 | Medium |
*-4.5.12 | Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates <= 4.5.12 - Authenticated (Contributor+) Stored Cross-Site Scripting | May 16, 2024 | 4.5.13 | Medium |
*-4.5.9 | Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates <= 4.5.9 - Authenticated (Contributor+) DOM-Based Cross-Site Scripting via "Social Icons" Block | April 18, 2024 | 4.5.10 | Medium |
*-4.5.3 | Essential Blocks for Gutenberg <= 4.5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting | April 5, 2024 | 4.5.4 | Medium |
*-4.4.9 | Essential Blocks for Gutenberg <= 4.4.9 - Missing Authorization | March 28, 2024 | 4.4.10 | Medium |
*-4.5.3 | Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates <= 4.5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting | March 19, 2024 | 4.5.4 | Medium |
*-4.5.1 | Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates <= 4.5.1 - Authenticated (Contributor+) Stored Cross-Site Scripting | February 28, 2024 | 4.5.2 | Medium |
*-4.4.6 | Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates <= 4.4.6 - Authenticated (Contributor+) Stored Cross-Site Scripting | January 9, 2024 | 4.4.7 | Medium |
*-4.2.0 | Essential Blocks for Gutenberg <= 4.2.0 - Incorrect Authorization Checks | December 26, 2023 | 4.2.1 | Medium |
*-4.4.2 | Essential Blocks <= 4.4.2 - Unauthenticated Local File Inclusion | December 21, 2023 | 4.4.3 | Critical |
*-4.2.0 | Essential Blocks for Gutenberg <= 4.2.0 - Missing Authorization via AJAX actions | November 13, 2023 | 4.2.1 | Medium |
*-4.2.0 | Essential Blocks <= 4.2.0 - Unauthenticated PHP Object Injection via queries | September 13, 2023 | 4.2.1 | High |
*-4.2.0 | Essential Blocks <= 4.2.0 - Unauthenticated PHP Object Injection via products | September 13, 2023 | 4.2.1 | High |
Selected source records
Published: June 24, 2026
Published: June 4, 2026
Published: May 1, 2026
Published: December 16, 2025
Published: October 17, 2025
Published: October 17, 2025
Published: May 26, 2025
Published: March 7, 2025
Published: December 21, 2023
Published: September 13, 2023
Published: September 13, 2023
Published: June 4, 2026
Published: June 24, 2026
Published: September 30, 2024
Published: May 1, 2026
Published: March 7, 2025
Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.
Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.
This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.