PLUGIN SECURITY

Is Essential Blocks safe?

Gutenberg block editor with AI. 70+ Gutenberg blocks, patterns, WooCommerce blocks, post grid, gallery, menu with Gutenberg block library.

What this plugin does

  • Slug: essential-blocks
  • Author: WPDeveloper
  • 200000+ active installs
  • 98/100 rating (213 reviews on wordpress.org)
  • 9188686 all-time downloads
  • On WordPress.org since 2018-12-09

block-editorGenerate with AIgutenbergGutenberg TemplatesGutenberg WooCommerce

Maintenance status

  • Latest known version: 6.4.1
  • Last updated: 2026-08-20 11:32am GMT
  • Tested up to WordPress: 7.0.4
  • Requires PHP: 7.4+
  • Max supported PHP (analyzed): 8.4

Known vulnerabilities

34 known CVEs on file for Essential Blocks.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-13154 Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns [essential-blocks] < 6.4.0 Exposure of Sensitive Information to an Unauthorized Actor Unknown < 6.4.0 6.4.0 2026-08-06 ✓ fixed in latest
CVE-2026-13153 Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns [essential-blocks] < 6.4.0 Exposure of Sensitive Information to an Unauthorized Actor Unknown < 6.4.0 6.4.0 2026-08-06 ✓ fixed in latest
CVE-2026-10833 Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns [essential-blocks] < 6.2.0 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 6.2.0 6.2.0 2026-06-24 ✓ fixed in latest
CVE-2026-10586 Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns [essential-blocks] < 6.1.4 Server-Side Request Forgery (SSRF) High 7.2 < 6.1.4 6.1.4 2026-06-04 ✓ fixed in latest
CVE-2026-4658 Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns [essential-blocks] < 6.1.0 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 6.1.0 6.1.0 2026-05-01 ✓ fixed in latest
CVE-2025-11369 Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns [essential-blocks] < 5.7.3 Missing Authorization Medium 4.3 < 5.7.3 5.7.3 2025-12-16 ✓ fixed in latest
CVE-2025-11270 Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns [essential-blocks] < 5.7.2 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 5.7.2 5.7.2 2025-10-17 ✓ fixed in latest
CVE-2025-11361 Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns [essential-blocks] < 5.7.2 Server-Side Request Forgery (SSRF) Medium 6.4 < 5.7.2 5.7.2 2025-10-17 ✓ fixed in latest
+ 28 more known vulnerabilities
CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-13803 Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns [essential-blocks] < 5.3.0 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 5.3.0 5.3.0 2025-02-25 ✓ fixed in latest
CVE-2025-26871 Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns [essential-blocks] < 4.8.4 Missing Authorization Medium 4.3 < 4.8.4 4.8.4 2025-02-22 ✓ fixed in latest
CVE-2024-12045 Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns [essential-blocks] < 5.1.1 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.4 < 5.1.1 5.1.1 2025-01-07 ✓ fixed in latest
CVE-2023-51360 Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns [essential-blocks] < 4.2.1 Missing Authorization Medium 6.5 < 4.2.1 4.2.1 2024-12-09 ✓ fixed in latest
CVE-2024-47385 Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns [essential-blocks] < 4.9.0 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.5 < 4.9.0 4.9.0 2024-09-30 ✓ fixed in latest
CVE-2024-5595 Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns [essential-blocks] < 4.7.0 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 4.7.0 4.7.0 2024-07-12 ✓ fixed in latest
CVE-2024-4891 Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns [essential-blocks] < 4.5.13 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 4.5.13 4.5.13 2024-05-16 ✓ fixed in latest
CVE-2024-3818 Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns [essential-blocks] < 4.5.10 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 4.5.10 4.5.10 2024-04-18 ✓ fixed in latest
CVE-2024-31306 Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns [essential-blocks] < 4.5.4 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 4.5.4 4.5.4 2024-04-05 ✓ fixed in latest
CVE-2024-30467 Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns [essential-blocks] < 4.4.10 Missing Authorization Medium 6.5 < 4.4.10 4.4.10 2024-03-28 ✓ fixed in latest
CVE-2024-2255 Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns [essential-blocks] < 4.5.4 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 4.5.4 4.5.4 2024-03-19 ✓ fixed in latest
CVE-2024-1854 Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns [essential-blocks] < 4.5.2 Improper Input Validation Medium 5.4 < 4.5.2 4.5.2 2024-02-28 ✓ fixed in latest
CVE-2023-7071 Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns [essential-blocks] < 4.4.7 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 4.4.7 4.4.7 2024-01-09 ✓ fixed in latest
CVE-2023-51359 Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns [essential-blocks] < 4.2.1 Missing Authorization Medium 5.4 < 4.2.1 4.2.1 2023-12-26 ✓ fixed in latest
CVE-2023-6623 Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns [essential-blocks] < 4.4.3 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Critical 9.8 < 4.4.3 4.4.3 2023-12-21 ✓ fixed in latest
CVE-2023-47760 Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns [essential-blocks] < 4.2.1 Missing Authorization Medium 4.3 < 4.2.1 4.2.1 2023-11-13 ✓ fixed in latest
CVE-2023-4386, CVE-2023-4402 Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns [essential-blocks] < 4.2.1 Deserialization of Untrusted Data High 8.1 < 4.2.1 4.2.1 2023-09-13 ✓ fixed in latest
CVE-2023-4402 Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns [essential-blocks] < 4.2.1 Deserialization of Untrusted Data Critical 9.8 < 4.2.1 4.2.1 2023-09-13 ✓ fixed in latest
CVE-2023-2085 Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns [essential-blocks] < 4.0.7 Missing Authorization Medium 4.3 < 4.0.7 4.0.7 2023-04-18 ✓ fixed in latest
CVE-2023-2086 Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns [essential-blocks] < 4.0.7 Missing Authorization Medium 4.3 < 4.0.7 4.0.7 2023-04-18 ✓ fixed in latest
CVE-2023-2087 Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns [essential-blocks] < 4.0.7 Cross-Site Request Forgery (CSRF) Medium 4.3 < 4.0.7 4.0.7 2023-04-18 ✓ fixed in latest
CVE-2023-2084 Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns [essential-blocks] < 4.0.7 Missing Authorization Medium 4.3 < 4.0.7 4.0.7 2023-04-18 ✓ fixed in latest
CVE-2023-2083, CVE-2023-2084, CVE-2023-2085, CVE-2023-2086, CVE-2023-2087 Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns [essential-blocks] < 4.0.7 Missing Authorization Medium 4.3 < 4.0.7 4.0.7 2023-04-18 ✓ fixed in latest
CVE-2022-47594 Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns [essential-blocks] < 3.8.6 Missing Authorization Medium 6.5 < 3.8.6 3.8.6 2023-01-20 ✓ fixed in latest
Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns [essential-blocks] < 5.3.2 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 5.3.2 5.3.2 0000-00-00 ✓ fixed in latest
Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns [essential-blocks] < 5.4.1 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 5.4.1 5.4.1 0000-00-00 ✓ fixed in latest
CVE-2025-1664 Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates < 5.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting Unknown < 5.3.2 5.3.2 ✓ fixed in latest
CVE-2025-4682 Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates < 5.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Slider and Post Carousel Widgets Unknown < 5.4.1 5.4.1 ✓ fixed in latest

How to fix it

Keep Essential Blocks updated — 6.4.1 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.