← Back

Genesis Blocks

genesis_blocks

Vendor: Wpengine • 3 CVEs

CVEs (3)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Wpengine
1Genesis Blocks
Nov 13, 2025
May 15, 2025
N/A· v4
6.8 MEDIUM· v3
N/A· v2
The Genesis Blocks WordPress plugin through 3.1.3 does not properly escape attributes provided to some of its custom blocks, making it possible for users allowed to write posts (like those with the contributor role) to c...Show more
The Genesis Blocks WordPress plugin through 3.1.3 does not properly escape attributes provided to some of its custom blocks, making it possible for users allowed to write posts (like those with the contributor role) to conduct Stored XSS attacks.Show less
1Wpengine
1Genesis Blocks
Apr 8, 2026
Jul 9, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
The Genesis Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Sharing block in all versions up to, and including, 3.1.3 due to insufficient input sanitization and output escaping o...Show more
The Genesis Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Sharing block in all versions up to, and including, 3.1.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE-2024-3901 is a duplicate of this issue.Show less
1Wpengine
1Genesis Blocks
May 30, 2025
Apr 19, 2024
N/A· v4
6.8 MEDIUM· v3
N/A· v2
The Genesis Blocks WordPress plugin before 3.1.3 does not properly escape data input provided to some of its blocks, allowing using with at least contributor privileges to conduct Stored XSS attacks.