CVE · Medium

CVE-2026-12900 — Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 2.19.29

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-12900 Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 2.19.29 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 2.19.29 2.19.29 2026-07-20

CVE-2026-12900

The Spectra Gutenberg Blocks plugin for WordPress contains a security flaw in its `uagb/image` block that allows malicious users with at least Contributor privileges to embed unauthorized code snippets into webpage content. This code is executed when the affected page is viewed, potentially leading to further exploitation by an attacker. The vulnerability affects all versions of the plugin up to 2.19.28.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.