PLUGIN SECURITY
Is Otter Blocks safe?
Quickly create WordPress pages with 20+ blocks, 100+ ready-to-import designs, and advanced editor extensions. It’s website building, Lego-style!
What this plugin does
- Slug:
otter-blocks - Author: Themeisle
- 300000+ active installs
- 94/100 rating (249 reviews on wordpress.org)
- 13827132 all-time downloads
- On WordPress.org since 2018-10-17
blocksfsegutenberggutenberg blockspage builder
Maintenance status
- Latest known version: 3.2.1
- Last updated: 2026-09-07 2:52pm GMT
- Tested up to WordPress: 7.1
- Requires PHP: 5.6+
Known vulnerabilities
13 known CVEs on file for Otter Blocks. Reported between 2023 and 2026.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2026-2892 | Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE [otter-blocks] < 3.1.5 | Improper Authorization | High 7.5 | < 3.1.5 | 3.1.5 | 2026-04-29 | ✓ fixed in latest |
| CVE-2026-4945 | Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE [otter-blocks] < 3.1.8 | Authorization Bypass Through User-Controlled Key | Medium 5.3 | < 3.1.8 | 3.1.8 | 2026-04-29 | ✓ fixed in latest |
| CVE-2025-55715 | Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE [otter-blocks] < 3.1.1 | Insertion of Sensitive Information Into Sent Data | High 7.5 | < 3.1.1 | 3.1.1 | 2025-08-20 | ✓ fixed in latest |
| CVE-2024-11219 | Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE [otter-blocks] < 3.0.7 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | Medium 5.3 | < 3.0.7 | 3.0.7 | 2024-11-26 | ✓ fixed in latest |
| CVE-2024-51671 | Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE [otter-blocks] < 3.0.4 | Missing Authorization | Low 2.7 | < 3.0.4 | 3.0.4 | 2024-11-01 | ✓ fixed in latest |
| CVE-2024-10367 | Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE [otter-blocks] < 3.0.5 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.4 | < 3.0.5 | 3.0.5 | 2024-10-31 | ✓ fixed in latest |
| CVE-2024-3725 | Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE [otter-blocks] < 2.6.10 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 2.6.10 | 2.6.10 | 2024-04-16 | ✓ fixed in latest |
| CVE-2024-3343 | Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE [otter-blocks] < 2.6.9 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 2.6.9 | 2.6.9 | 2024-04-10 | ✓ fixed in latest |
+ 5 more known vulnerabilities
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2024-3344 | Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE [otter-blocks] < 2.6.9 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 2.6.9 | 2.6.9 | 2024-04-10 | ✓ fixed in latest |
| CVE-2024-2841 | Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE [otter-blocks] < 2.6.6 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 2.6.6 | 2.6.6 | 2024-03-28 | ✓ fixed in latest |
| CVE-2024-2729 | Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE [otter-blocks] < 2.6.6 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 2.6.6 | 2.6.6 | 2024-03-28 | ✓ fixed in latest |
| CVE-2024-2226 | Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE [otter-blocks] < 2.6.5 | Improper Input Validation | Medium 5.4 | < 2.6.5 | 2.6.5 | 2024-03-13 | ✓ fixed in latest |
| CVE-2023-2288 | Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE [otter-blocks] < 2.2.6 | Deserialization of Untrusted Data | High 8.8 | < 2.2.6 | 2.2.6 | 2023-05-02 | ✓ fixed in latest |
How to fix it
Keep Otter Blocks updated — 3.2.1 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
- Spectra Legacy – Gutenberg Blocks — 1000000+ active installs — 94/100 (1870) — max PHP 8.4
- Kadence Blocks — Page Builder Toolkit for Gutenberg Editor — 600000+ active installs — 96/100 (332) — max PHP 8.4
- Page Builder: Pagelayer – Drag and Drop website builder — 400000+ active installs — 78/100 (103) — max PHP 8.4
- Page Builder Gutenberg Blocks – CoBlocks — 300000+ active installs — 86/100 (108)
- Stackable – Page Builder Gutenberg Blocks — 100000+ active installs — 98/100 (521)
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.