+ 27 vulnerabilidades conocidas más
| CVE |
Vulnerabilidad |
Tipo |
Gravedad |
Afectadas |
Corregido en |
Publicado |
Estado |
|
CVE-2024-1815
|
Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 2.12.9 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
5,4
|
< 2.12.9
|
2.12.9 |
2024-05-22 |
✓ corregido en la última versión
|
|
CVE-2024-1814
|
Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 2.12.9 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
5,4
|
< 2.12.9
|
2.12.9 |
2024-05-22 |
✓ corregido en la última versión
|
|
CVE-2024-3107
|
Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 2.12.7 |
Limitación incorrecta de una ruta a un directorio restringido (Path Traversal) |
Media
4,3
|
< 2.12.7
|
2.12.7 |
2024-04-26 |
✓ corregido en la última versión
|
|
CVE-2023-6486
|
Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 2.10.4 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
5,4
|
< 2.10.4
|
2.10.4 |
2024-04-03 |
✓ corregido en la última versión
|
|
CVE-2023-49833
|
Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 2.7.10 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
6,5
|
< 2.7.10
|
2.7.10 |
2023-12-05 |
✓ corregido en la última versión
|
|
CVE-2023-36676
|
Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 2.6.7 |
Falta de control de autorización |
Media
5,4
|
< 2.6.7
|
2.6.7 |
2023-07-14 |
✓ corregido en la última versión
|
|
CVE-2023-36679
|
Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 2.6.7 |
Falsificación de petición del lado del servidor (SSRF) |
Alta
7,1
|
< 2.6.7
|
2.6.7 |
2023-07-14 |
✓ corregido en la última versión
|
|
—
|
Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 2.6.7 |
— |
Desconocido
|
< 2.6.7
|
2.6.7 |
2023-07-14 |
✓ corregido en la última versión
|
|
—
|
Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 2.3.3 |
— |
Desconocido
|
< 2.3.3
|
2.3.3 |
2023-01-25 |
✓ corregido en la última versión
|
|
—
|
Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 2.3.2 |
— |
Desconocido
|
< 2.3.2
|
2.3.2 |
2023-01-25 |
✓ corregido en la última versión
|
|
CVE-2020-36656
|
Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 1.15.0 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
5,4
|
< 1.15.0
|
1.15.0 |
2023-01-24 |
✓ corregido en la última versión
|
|
CVE-2023-23729
|
Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 2.3.2 |
Falta de control de autorización |
Media
5,4
|
< 2.3.2
|
2.3.2 |
2023-01-23 |
✓ corregido en la última versión
|
|
CVE-2023-23738
|
Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 2.3.2 |
Neutralización incorrecta de elementos especiales en la salida usada por un componente posterior (inyección) |
Media
5,3
|
< 2.3.2
|
2.3.2 |
2023-01-23 |
✓ corregido en la última versión
|
|
CVE-2023-23735
|
Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 2.3.2 |
Neutralización incorrecta de etiquetas HTML relacionadas con scripts en una página web (XSS básico) |
Media
5,3
|
< 2.3.2
|
2.3.2 |
2023-01-23 |
✓ corregido en la última versión
|
|
CVE-2023-23730
|
Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 2.3.2 |
Restricción incorrecta de intentos excesivos de autenticación |
Media
5,3
|
< 2.3.2
|
2.3.2 |
2023-01-23 |
✓ corregido en la última versión
|
|
CVE-2023-23825
|
Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 2.3.2 |
Falta de control de autorización |
Baja
3,1
|
< 2.3.2
|
2.3.2 |
2023-01-23 |
✓ corregido en la última versión
|
|
CVE-2023-23834
|
Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 2.3.1 |
Falta de control de autorización |
Media
4,3
|
< 2.3.1
|
2.3.1 |
2023-01-23 |
✓ corregido en la última versión
|
|
—
|
Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 1.25.6 |
— |
Desconocido
|
< 1.25.6
|
1.25.6 |
2022-06-13 |
✓ corregido en la última versión
|
|
—
|
Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 1.25.6 |
— |
Desconocido
|
< 1.25.6
|
1.25.6 |
2022-05-31 |
✓ corregido en la última versión
|
|
—
|
Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 1.14.8 |
— |
Desconocido
|
< 1.14.8
|
1.14.8 |
2020-04-08 |
✓ corregido en la última versión
|
|
CVE-2020-36702
|
Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 1.14.8 |
Falta de control de autorización |
Media
5,5
|
< 1.14.8
|
1.14.8 |
2020-03-30 |
✓ corregido en la última versión
|
|
CVE-2025-1784
|
Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 2.19.1 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
6,4
|
< 2.19.1
|
2.19.1 |
0000-00-00 |
✓ corregido en la última versión
|
|
CVE-2026-0950
|
Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 2.19.18 |
— |
Desconocido
|
< 2.19.18
|
2.19.18 |
0000-00-00 |
✓ corregido en la última versión
|
|
—
|
Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 1.25.6 |
— |
Desconocido
|
< 1.25.6
|
1.25.6 |
— |
✓ corregido en la última versión
|
|
—
|
Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 1.14.8 |
— |
Desconocido
|
< 1.14.8
|
1.14.8 |
— |
✓ corregido en la última versión
|
|
—
|
Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 1.14.8 |
— |
Desconocido
|
< 1.14.8
|
1.14.8 |
— |
✓ corregido en la última versión
|
|
—
|
Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 2.19.26 |
— |
Desconocido
|
< 2.19.26
|
2.19.26 |
— |
✓ corregido en la última versión
|
CVE-2024-1815
The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Gallery block in all versions up to, and including, 2.12.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2024-1814
The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Testimonial block in all versions up to, and including, 2.12.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2024-3107
The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Path Traversal in versions up to, and including, 2.12.6 via the get_block_default_attributes function. This allows authenticated attackers, with contributor-level permissions and above, to read the contents of any files named attributes.php on the server, which can contain sensitive information.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2023-6486
Update the WordPress Spectra plugin to the latest available version (at least 2.10.4).
Akbar Kustirama discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Spectra Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 2.10.4.
Have additional information or questions about this entry? Get in touch.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2023-49833
Update the WordPress Spectra plugin to the latest available version (at least 2.7.10).
Rafie Muhammad (Patchstack) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Spectra Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 2.7.10.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2023-36676
The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.6.6. This makes it possible for authenticated attackers, with Contributor-level access and above, to perform an unauthorized action.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2023-36679
Update the WordPress Spectra plugin to the latest available version (at least 2.6.7).
Rafie Muhammad (Patchstack) discovered and reported this Server Side Request Forgery (SSRF) vulnerability in WordPress Spectra Plugin. This could allow a malicious actor to cause a website to execute website requests to an arbitrary domain of the attacker. This could allow a malicious actor to find sensitive information of other services running on the system. This vulnerability has been fixed in version 2.6.7.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 2.6.7
The Spectra plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 2.6.6 via the template_importer function. This can allow authenticated attackers, with contributor-level permissions and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 2.3.3
The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.3.1 This is due to missing nonce validation on the activate_plugin function called via an AJAX action. This makes it possible for unauthenticated attackers to activate arbitrary plugins, via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 2.3.2
The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the import_wpforms, import_block, and activate_plugin functions called via AJAX actions in versions up to, and including, 2.3.1. This makes it possible for authenticated attackers, such as subscribers, to activate arbitrary plugins and import blocks and forms from WPForms.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2020-36656
Update the WordPress Spectra plugin to the latest available version (at least 1.15.0).
Lana Codes discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Spectra Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 1.15.0.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2023-23729
The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the forms_recaptcha function in versions up to, and including, 2.3.1. This makes it possible for authenticated attackers with contributor-level permissions and above to modify the plugin's Captcha settings.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2023-23738
Update the WordPress Gutenberg Blocks plugin to the latest available version (at least 2.3.1).
Dave Jong (Patchstack) discovered and reported this Content Spoofing vulnerability in WordPress Spectra Plugin. This could allow a malicious actor to inject their own content into pages and posts of your website. This could also be abused to inject phishing pages into your website. This vulnerability has been fixed in version 2.3.1.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2023-23735
Update the WordPress Gutenberg Blocks plugin to the latest available version (at least 2.3.1).
Dave Jong (Patchstack) discovered and reported this Content Injection vulnerability in WordPress Spectra Plugin. This could allow a malicious actor to inject their own content into pages and posts of your website. This could also be abused to inject phishing pages into your website. This vulnerability has been fixed in version 2.3.1.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2023-23730
Update the WordPress Gutenberg Blocks plugin to the latest available version (at least 2.3.1).
Dave Jong (Patchstack) discovered and reported this Bypass Vulnerability vulnerability in WordPress Spectra Plugin. A bypass vulnerability could allow a malicious actor to bypass certain restrictions in the code. For example a way to bypass certain authorization checks which might allow a malicious actor to gain access to the admin panel. This vulnerability has been fixed in version 2.3.1.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2023-23825
The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.3.1 This is due to missing nonce validation on the import_wpforms and import_block functions called via AJAX actions. This makes it possible for unauthenticated attackers to import blocks and forms from WPForms. via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2023-23834
Update the WordPress Gutenberg Blocks plugin to the latest available version (at least 2.3.1).
Lana Codes discovered and reported this Broken Access Control vulnerability in WordPress Spectra Plugin. This vulnerability has been fixed in version 2.3.1.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 1.25.6
Reflected Cross-Site Scripting (XSS) vulnerability discovered by WPScanTeam in WordPress Spectra plugin (versions <= 1.25.5).
Update the WordPress Spectra plugin to the latest available version (at least 1.25.6).
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 1.25.6
The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in versions up to, and including, 1.25.5. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 1.14.8
Authenticated Settings Change vulnerability discovered by NinTechNet in WordPress Gutenberg Blocks plugin (versions <= 1.14.7).
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2020-36702
The Ultimate Addons for Gutenberg plugin for WordPress is vulnerable to Authenticated Settings Change in versions up to, and including, 1.14.7. This is due to missing capability checks on several AJAX actions. This makes it possible for authenticated attackers with subscriber+ roles to update the plugin's settings.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2025-1784
The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the uagb block in all versions up to, and including, 2.19.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2026-0950
The Spectra Gutenberg Blocks – Website Builder for the Block Editor plugin for WordPress is vulnerable to Information Disclosure in all versions up to, and including, 2.19.17. This is due to the plugin failing to check `post_password_required()` before rendering post excerpts in the `render_excerpt()` function and the `uagb_get_excerpt()` helper function. This makes it possible for unauthenticated attackers to read excerpts of password-protected posts by simply viewing any page that contains a Spectra Post Grid, Post Masonry, Post Carousel, or Post Timeline block.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 1.25.6
The plugin does not escape some URLs before outputting them back in attributes, leading to Reflected Cross-Site Scripting
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
WPScan
Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 1.14.8
The Gutenberg Blocks – Ultimate Addons for Gutenberg WordPress plugin was affected by an Ultimate Addons for Gutenberg < 1.14.8 - Authenticated Settings Change security vulnerability.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
WPScan
Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 1.14.8
The Ultimate Addons for Gutenberg plugin for WordPress is vulnerable to Authenticated Settings Change in versions up to, and including, 1.14.7. This is due to [state why the vulnerability is created]. This makes it possible for authenticated attackers with Subscriber+ roles to update WordPress settings.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 2.19.26
The Spectra Gutenberg Blocks – Website Builder for the Block Editor plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.19.25. This makes it possible for authenticated attackers, with Contributor-level access and above, to execute code on the server. Exploitation requires a two-block payload embedded in post content: the first block registers a fake uagb/-prefixed block type with an attacker-specified render_callback, and the second block of the same fake type triggers invocation of that callback via call_user_func() during sequential block rendering in the same page request.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
Mantén Spectra actualizado — 2.20.0 es la última versión en wordpress.org, y cada CVE de arriba indica la versión exacta que lo corrigió ("Corregido en").
Este es el historial completo de vulnerabilidades conocidas del plugin, no un escaneo de una instalación específica — ejecuta un escaneo gratis de tu propio sitio para verificar tu versión instalada exacta.