CVE Database /
CVE-2026-12900
CVE · Medium
CVE-2026-12900 — Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 2.19.29
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-12900
|
Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 2.19.29 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
6.4
|
< 2.19.29
|
2.19.29 |
2026-07-20 |
—
|
CVE-2026-12900
The Spectra Gutenberg Blocks plugin for WordPress contains a security flaw in its `uagb/image` block that allows malicious users with at least Contributor privileges to embed unauthorized code snippets into webpage content. This code is executed when the affected page is viewed, potentially leading to further exploitation by an attacker. The vulnerability affects all versions of the plugin up to 2.19.28.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings