PLUGIN SECURITY

Is Spectra safe?

Gutenberg blocks for existing Spectra websites. Maintained, stable, and fully supported — no action needed on your part.

What this plugin does

  • Slug: ultimate-addons-for-gutenberg
  • Author: Brainstorm Force
  • 1000000+ active installs
  • 94/100 rating (1870 reviews on wordpress.org)
  • 43360136 all-time downloads
  • On WordPress.org since 2018-06-13

blockblockseditorgutenberggutenberg blocks

Maintenance status

  • Latest known version: 2.20.1
  • Last updated: 2026-08-26 12:07pm GMT
  • Tested up to WordPress: 7.1
  • Requires PHP: 7.4+
  • Max supported PHP (analyzed): 8.4

Known vulnerabilities

27 known CVEs on file for Spectra.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-12900 Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 2.19.29 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 2.19.29 2.19.29 2026-07-20 ✓ fixed in latest
CVE-2026-10827 Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 2.20.0 Insufficient Verification of Data Authenticity Unknown < 2.20.0 2.20.0 2026-07-20 ✓ fixed in latest
CVE-2026-7465 Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 2.19.26 Improper Privilege Management High 8.8 < 2.19.26 2.19.26 2026-05-29 ✓ fixed in latest
CVE-2026-42648 Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 2.19.23 Medium 4.3 < 2.19.23 2.19.23 2026-03-27 ✓ fixed in latest
CVE-2026-24982 Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 2.19.18 Missing Authorization Medium 5.3 < 2.19.18 2.19.18 2026-01-17 ✓ fixed in latest
CVE-2025-11162 Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 2.19.15 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 2.19.15 2.19.15 2025-11-04 ✓ fixed in latest
CVE-2024-10484 Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 2.16.3 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 2.16.3 2.16.3 2024-12-02 ✓ fixed in latest
CVE-2024-7590 Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 2.15.1 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.5 < 2.15.1 2.15.1 2024-08-07 ✓ fixed in latest
+ 31 more known vulnerabilities
CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-37517 Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 2.13.8 Missing Authorization High 8.8 < 2.13.8 2.13.8 2024-07-05 ✓ fixed in latest
CVE-2024-4366 Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 2.13.1 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 2.13.1 2.13.1 2024-05-23 ✓ fixed in latest
CVE-2024-1815 Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 2.12.9 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 2.12.9 2.12.9 2024-05-22 ✓ fixed in latest
CVE-2024-1814 Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 2.12.9 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 2.12.9 2.12.9 2024-05-22 ✓ fixed in latest
CVE-2024-3107 Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 2.12.7 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Medium 4.3 < 2.12.7 2.12.7 2024-04-26 ✓ fixed in latest
CVE-2023-6486 Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 2.10.4 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 2.10.4 2.10.4 2024-04-03 ✓ fixed in latest
CVE-2023-49833 Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 2.7.10 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.5 < 2.7.10 2.7.10 2023-12-05 ✓ fixed in latest
CVE-2023-36676 Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 2.6.7 Missing Authorization Medium 5.4 < 2.6.7 2.6.7 2023-07-14 ✓ fixed in latest
CVE-2023-36679 Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 2.6.7 Server-Side Request Forgery (SSRF) High 7.1 < 2.6.7 2.6.7 2023-07-14 ✓ fixed in latest
Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 2.6.7 Unknown < 2.6.7 2.6.7 2023-07-14 ✓ fixed in latest
Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 2.3.2 Unknown < 2.3.2 2.3.2 2023-01-25 ✓ fixed in latest
CVE-2020-36656 Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 1.15.0 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 1.15.0 1.15.0 2023-01-24 ✓ fixed in latest
CVE-2023-23834 Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 2.3.3 Missing Authorization Medium 4.3 < 2.3.3 2.3.3 2023-01-23 ✓ fixed in latest
CVE-2023-23729 Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 2.3.2 Missing Authorization Medium 5.4 < 2.3.2 2.3.2 2023-01-23 ✓ fixed in latest
CVE-2023-23738 Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 2.3.2 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') Medium 5.3 < 2.3.2 2.3.2 2023-01-23 ✓ fixed in latest
CVE-2023-23735 Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 2.3.2 Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) Medium 5.3 < 2.3.2 2.3.2 2023-01-23 ✓ fixed in latest
CVE-2023-23730 Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 2.3.2 Improper Restriction of Excessive Authentication Attempts Medium 5.3 < 2.3.2 2.3.2 2023-01-23 ✓ fixed in latest
CVE-2023-23825 Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 2.3.2 Missing Authorization Low 3.1 < 2.3.2 2.3.2 2023-01-23 ✓ fixed in latest
Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 1.25.6 Unknown < 1.25.6 1.25.6 2022-06-13 ✓ fixed in latest
Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 1.25.6 Unknown < 1.25.6 1.25.6 2022-05-31 ✓ fixed in latest
Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 1.14.8 Unknown < 1.14.8 1.14.8 2020-04-08 ✓ fixed in latest
CVE-2020-36702 Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 1.14.8 Missing Authorization Medium 5.5 < 1.14.8 1.14.8 2020-03-30 ✓ fixed in latest
Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 2.19.1 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 2.19.1 2.19.1 0000-00-00 ✓ fixed in latest
Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 2.19.18 Unknown < 2.19.18 2.19.18 0000-00-00 ✓ fixed in latest
Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 1.25.6 Unknown < 1.25.6 1.25.6 ✓ fixed in latest
Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 1.14.8 Unknown < 1.14.8 1.14.8 ✓ fixed in latest
Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 1.14.8 Unknown < 1.14.8 1.14.8 ✓ fixed in latest
Spectra < 1.25.6 - Reflected Cross-Site Scripting Unknown < 1.25.6 1.25.6 ✓ fixed in latest
CVE-2025-1784 Spectra < 2.19.1 - Contributor+ Stored XSS Unknown < 2.19.1 2.19.1 ✓ fixed in latest
CVE-2026-0950 Spectra Gutenberg Blocks < 2.19.18 - Unauthenticated Information Disclosure in Sensitive Data Unknown < 2.19.18 2.19.18 ✓ fixed in latest
CVE-2026-7465 Spectra < 2.19.26 - Contributor+ Remote Code Execution via Block Attributes Unknown < 2.19.26 2.19.26 ✓ fixed in latest

How to fix it

Keep Spectra updated — 2.20.1 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.