WP Clinic
Entrar Registrarse

SEGURIDAD DE PLUGINS

¿Es seguro Spectra?

Vulnerabilidades conocidas, compatibilidad con PHP y alternativas más seguras para el plugin de WordPress Spectra — verificado contra la base de datos de seguridad local de WP Clinic.

Qué hace este plugin

  • Slug: ultimate-addons-for-gutenberg
  • 1000000+ instalaciones activas

blockblockseditorgutenberggutenberg blocks

Estado de mantenimiento

  • Última versión conocida: 2.20.0
  • Requiere PHP: 7.4+
  • PHP máximo soportado (analizado): 8.4

Vulnerabilidades conocidas

25 CVEs conocidos registrados para Spectra.

CVE Vulnerabilidad Tipo Gravedad Afectadas Corregido en Publicado Estado
CVE-2026-7465 Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 2.19.26 Gestión incorrecta de privilegios Alta 8,8 < 2.19.26 2.19.26 2026-05-29 ✓ corregido en la última versión
CVE-2026-42648 Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 2.19.23 Media 4,3 < 2.19.23 2.19.23 2026-03-27 ✓ corregido en la última versión
CVE-2026-24982 Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 2.19.18 Falta de control de autorización Media 5,3 < 2.19.18 2.19.18 2026-01-17 ✓ corregido en la última versión
CVE-2025-11162 Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 2.19.15 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,4 < 2.19.15 2.19.15 2025-11-04 ✓ corregido en la última versión
CVE-2024-10484 Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 2.16.3 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,4 < 2.16.3 2.16.3 2024-12-02 ✓ corregido en la última versión
CVE-2024-7590 Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 2.15.1 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,5 < 2.15.1 2.15.1 2024-08-07 ✓ corregido en la última versión
CVE-2024-37517 Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 2.13.8 Falta de control de autorización Alta 8,8 < 2.13.8 2.13.8 2024-07-05 ✓ corregido en la última versión
CVE-2024-4366 Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 2.13.1 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 2.13.1 2.13.1 2024-05-23 ✓ corregido en la última versión

CVE-2026-7465

The Spectra Gutenberg Blocks – Website Builder for the Block Editor plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.19.25. This makes it possible for authenticated attackers, with Contributor-level access and above, to execute code on the server. Exploitation requires a two-block payload embedded in post content: the first block registers a fake uagb/-prefixed block type with an attacker-specified render_callback, and the second block of the same fake type triggers invocation of that callback via call_user_func() during sequential block rendering in the same page request.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2026-42648

The Spectra plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.19.22. This makes it possible for authenticated attackers, with contributor-level access and above, to perform an unauthorized action.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2026-24982

The Spectra Gutenberg Blocks – Website Builder for the Block Editor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.19.17. This makes it possible for unauthenticated attackers to perform an unauthorized action.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2025-11162

The Spectra Gutenberg Blocks – Website Builder for the Block Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custom CSS in all versions up to, and including, 2.19.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2024-10484

The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'Team' widget in all versions up to, and including, 2.16.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2024-7590

The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the FAQ heading tag in all versions up to, and including, 2.15.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2024-37517

The Spectra plugin for WordPress is vulnerable to unauthorized modification of data due to an insufficient capability check on the generate_ai_content() function in versions up to, and including, 2.13.7. This makes it possible for authenticated attackers, with contributor-level access and above, to generate AI content.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2024-4366

The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘block_id’ parameter in versions up to, and including, 2.13.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

+ 27 vulnerabilidades conocidas más
CVE Vulnerabilidad Tipo Gravedad Afectadas Corregido en Publicado Estado
CVE-2024-1815 Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 2.12.9 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 2.12.9 2.12.9 2024-05-22 ✓ corregido en la última versión
CVE-2024-1814 Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 2.12.9 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 2.12.9 2.12.9 2024-05-22 ✓ corregido en la última versión
CVE-2024-3107 Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 2.12.7 Limitación incorrecta de una ruta a un directorio restringido (Path Traversal) Media 4,3 < 2.12.7 2.12.7 2024-04-26 ✓ corregido en la última versión
CVE-2023-6486 Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 2.10.4 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 2.10.4 2.10.4 2024-04-03 ✓ corregido en la última versión
CVE-2023-49833 Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 2.7.10 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,5 < 2.7.10 2.7.10 2023-12-05 ✓ corregido en la última versión
CVE-2023-36676 Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 2.6.7 Falta de control de autorización Media 5,4 < 2.6.7 2.6.7 2023-07-14 ✓ corregido en la última versión
CVE-2023-36679 Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 2.6.7 Falsificación de petición del lado del servidor (SSRF) Alta 7,1 < 2.6.7 2.6.7 2023-07-14 ✓ corregido en la última versión
Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 2.6.7 Desconocido < 2.6.7 2.6.7 2023-07-14 ✓ corregido en la última versión
Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 2.3.3 Desconocido < 2.3.3 2.3.3 2023-01-25 ✓ corregido en la última versión
Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 2.3.2 Desconocido < 2.3.2 2.3.2 2023-01-25 ✓ corregido en la última versión
CVE-2020-36656 Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 1.15.0 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 1.15.0 1.15.0 2023-01-24 ✓ corregido en la última versión
CVE-2023-23729 Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 2.3.2 Falta de control de autorización Media 5,4 < 2.3.2 2.3.2 2023-01-23 ✓ corregido en la última versión
CVE-2023-23738 Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 2.3.2 Neutralización incorrecta de elementos especiales en la salida usada por un componente posterior (inyección) Media 5,3 < 2.3.2 2.3.2 2023-01-23 ✓ corregido en la última versión
CVE-2023-23735 Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 2.3.2 Neutralización incorrecta de etiquetas HTML relacionadas con scripts en una página web (XSS básico) Media 5,3 < 2.3.2 2.3.2 2023-01-23 ✓ corregido en la última versión
CVE-2023-23730 Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 2.3.2 Restricción incorrecta de intentos excesivos de autenticación Media 5,3 < 2.3.2 2.3.2 2023-01-23 ✓ corregido en la última versión
CVE-2023-23825 Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 2.3.2 Falta de control de autorización Baja 3,1 < 2.3.2 2.3.2 2023-01-23 ✓ corregido en la última versión
CVE-2023-23834 Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 2.3.1 Falta de control de autorización Media 4,3 < 2.3.1 2.3.1 2023-01-23 ✓ corregido en la última versión
Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 1.25.6 Desconocido < 1.25.6 1.25.6 2022-06-13 ✓ corregido en la última versión
Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 1.25.6 Desconocido < 1.25.6 1.25.6 2022-05-31 ✓ corregido en la última versión
Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 1.14.8 Desconocido < 1.14.8 1.14.8 2020-04-08 ✓ corregido en la última versión
CVE-2020-36702 Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 1.14.8 Falta de control de autorización Media 5,5 < 1.14.8 1.14.8 2020-03-30 ✓ corregido en la última versión
CVE-2025-1784 Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 2.19.1 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,4 < 2.19.1 2.19.1 0000-00-00 ✓ corregido en la última versión
CVE-2026-0950 Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 2.19.18 Desconocido < 2.19.18 2.19.18 0000-00-00 ✓ corregido en la última versión
Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 1.25.6 Desconocido < 1.25.6 1.25.6 ✓ corregido en la última versión
Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 1.14.8 Desconocido < 1.14.8 1.14.8 ✓ corregido en la última versión
Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 1.14.8 Desconocido < 1.14.8 1.14.8 ✓ corregido en la última versión
Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 2.19.26 Desconocido < 2.19.26 2.19.26 ✓ corregido en la última versión

CVE-2024-1815

The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Gallery block in all versions up to, and including, 2.12.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2024-1814

The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Testimonial block in all versions up to, and including, 2.12.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2024-3107

The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Path Traversal in versions up to, and including, 2.12.6 via the get_block_default_attributes function. This allows authenticated attackers, with contributor-level permissions and above, to read the contents of any files named attributes.php on the server, which can contain sensitive information.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2023-6486

Update the WordPress Spectra plugin to the latest available version (at least 2.10.4). Akbar Kustirama discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Spectra Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 2.10.4. Have additional information or questions about this entry? Get in touch.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2023-49833

Update the WordPress Spectra plugin to the latest available version (at least 2.7.10). Rafie Muhammad (Patchstack) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Spectra Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 2.7.10.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2023-36676

The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.6.6. This makes it possible for authenticated attackers, with Contributor-level access and above, to perform an unauthorized action.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2023-36679

Update the WordPress Spectra plugin to the latest available version (at least 2.6.7). Rafie Muhammad (Patchstack) discovered and reported this Server Side Request Forgery (SSRF) vulnerability in WordPress Spectra Plugin. This could allow a malicious actor to cause a website to execute website requests to an arbitrary domain of the attacker. This could allow a malicious actor to find sensitive information of other services running on the system. This vulnerability has been fixed in version 2.6.7.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 2.6.7

The Spectra plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 2.6.6 via the template_importer function. This can allow authenticated attackers, with contributor-level permissions and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 2.3.3

The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.3.1 This is due to missing nonce validation on the activate_plugin function called via an AJAX action. This makes it possible for unauthenticated attackers to activate arbitrary plugins, via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 2.3.2

The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the import_wpforms, import_block, and activate_plugin functions called via AJAX actions in versions up to, and including, 2.3.1. This makes it possible for authenticated attackers, such as subscribers, to activate arbitrary plugins and import blocks and forms from WPForms.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2020-36656

Update the WordPress Spectra plugin to the latest available version (at least 1.15.0). Lana Codes discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Spectra Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 1.15.0.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2023-23729

The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the forms_recaptcha function in versions up to, and including, 2.3.1. This makes it possible for authenticated attackers with contributor-level permissions and above to modify the plugin's Captcha settings.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2023-23738

Update the WordPress Gutenberg Blocks plugin to the latest available version (at least 2.3.1). Dave Jong (Patchstack) discovered and reported this Content Spoofing vulnerability in WordPress Spectra Plugin. This could allow a malicious actor to inject their own content into pages and posts of your website. This could also be abused to inject phishing pages into your website. This vulnerability has been fixed in version 2.3.1.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2023-23735

Update the WordPress Gutenberg Blocks plugin to the latest available version (at least 2.3.1). Dave Jong (Patchstack) discovered and reported this Content Injection vulnerability in WordPress Spectra Plugin. This could allow a malicious actor to inject their own content into pages and posts of your website. This could also be abused to inject phishing pages into your website. This vulnerability has been fixed in version 2.3.1.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2023-23730

Update the WordPress Gutenberg Blocks plugin to the latest available version (at least 2.3.1). Dave Jong (Patchstack) discovered and reported this Bypass Vulnerability vulnerability in WordPress Spectra Plugin. A bypass vulnerability could allow a malicious actor to bypass certain restrictions in the code. For example a way to bypass certain authorization checks which might allow a malicious actor to gain access to the admin panel. This vulnerability has been fixed in version 2.3.1.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2023-23825

The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.3.1 This is due to missing nonce validation on the import_wpforms and import_block functions called via AJAX actions. This makes it possible for unauthenticated attackers to import blocks and forms from WPForms. via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2023-23834

Update the WordPress Gutenberg Blocks plugin to the latest available version (at least 2.3.1). Lana Codes discovered and reported this Broken Access Control vulnerability in WordPress Spectra Plugin. This vulnerability has been fixed in version 2.3.1.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 1.25.6

Reflected Cross-Site Scripting (XSS) vulnerability discovered by WPScanTeam in WordPress Spectra plugin (versions <= 1.25.5). Update the WordPress Spectra plugin to the latest available version (at least 1.25.6).

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 1.25.6

The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in versions up to, and including, 1.25.5. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 1.14.8

Authenticated Settings Change vulnerability discovered by NinTechNet in WordPress Gutenberg Blocks plugin (versions <= 1.14.7).

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2020-36702

The Ultimate Addons for Gutenberg plugin for WordPress is vulnerable to Authenticated Settings Change in versions up to, and including, 1.14.7. This is due to missing capability checks on several AJAX actions. This makes it possible for authenticated attackers with subscriber+ roles to update the plugin's settings.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2025-1784

The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the uagb block in all versions up to, and including, 2.19.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2026-0950

The Spectra Gutenberg Blocks – Website Builder for the Block Editor plugin for WordPress is vulnerable to Information Disclosure in all versions up to, and including, 2.19.17. This is due to the plugin failing to check `post_password_required()` before rendering post excerpts in the `render_excerpt()` function and the `uagb_get_excerpt()` helper function. This makes it possible for unauthenticated attackers to read excerpts of password-protected posts by simply viewing any page that contains a Spectra Post Grid, Post Masonry, Post Carousel, or Post Timeline block.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 1.25.6

The plugin does not escape some URLs before outputting them back in attributes, leading to Reflected Cross-Site Scripting

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 1.14.8

The Gutenberg Blocks – Ultimate Addons for Gutenberg WordPress plugin was affected by an Ultimate Addons for Gutenberg < 1.14.8 - Authenticated Settings Change security vulnerability.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 1.14.8

The Ultimate Addons for Gutenberg plugin for WordPress is vulnerable to Authenticated Settings Change in versions up to, and including, 1.14.7. This is due to [state why the vulnerability is created]. This makes it possible for authenticated attackers with Subscriber+ roles to update WordPress settings.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 2.19.26

The Spectra Gutenberg Blocks – Website Builder for the Block Editor plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.19.25. This makes it possible for authenticated attackers, with Contributor-level access and above, to execute code on the server. Exploitation requires a two-block payload embedded in post content: the first block registers a fake uagb/-prefixed block type with an attacker-specified render_callback, and the second block of the same fake type triggers invocation of that callback via call_user_func() during sequential block rendering in the same page request.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Cómo solucionarlo

Mantén Spectra actualizado — 2.20.0 es la última versión en wordpress.org, y cada CVE de arriba indica la versión exacta que lo corrigió ("Corregido en").

Este es el historial completo de vulnerabilidades conocidas del plugin, no un escaneo de una instalación específica — ejecuta un escaneo gratis de tu propio sitio para verificar tu versión instalada exacta.

Alternativas más seguras / más establecidas

Verifica tu propio sitio WordPress

Ejecuta un escaneo pasivo gratis ahora, o crea una cuenta gratuita e instala el plugin de WP Clinic para un escaneo profundo de toda tu cuenta de hosting y reparación asistida por IA.