Plugin Vulnerability Hub
Plugin 12 known issues Latest disclosed Apr 29, 2026

Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE Vulnerabilities

Review known vulnerability records for the WordPress plugin Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE (`otter-blocks`), including severity, CVE references, affected versions, and patch status.

Recent tracked CVEs on this page include CVE-2026-2892, CVE-2025-55715 and CVE-2024-11219, so operators can jump from disclosure to patch validation without scanning the full feed first.

Known Records
12
High or Critical
2
Patch Coverage
100%
Last Updated
Apr 30, 2026
Priority CVE Quick Links

Fast paths into Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE CVE reports

Start with the highest-signal CVE records for this WordPress plugin before scanning the full vulnerability feed.

Indexed CVEs
12
CVE-2023-2288 High 2.2.6
CVE-2023-2288 Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE Vulnerability

Otter - Gutenberg Blocks <= 2.2.5 - Authenticated (Author+) PHAR Deserialization

CVE-2026-2892 High 3.1.5
CVE-2026-2892 Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE Vulnerability

Otter Blocks <= 3.1.4 - Improper Authorization to Unauthenticated Purchase Verification Bypass via Forged Cookie

CVE-2024-10367 Medium 3.0.5
CVE-2024-10367 Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE File Upload

Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE <= 3.0.4 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload

CVE-2024-3725 Medium 2.6.10
CVE-2024-3725 Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE Stored Cross-Site Scripting

Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE <= 2.6.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'titleTag'

CVE-2024-3344 Medium 2.6.9
CVE-2024-3344 Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE File Upload

Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE <= 2.6.8 - Authenticated (Author+) Limited File Upload to Stored Cross-Site Scripting

CVE-2024-3343 Medium 2.6.9
CVE-2024-3343 Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE Stored Cross-Site Scripting

Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE <= 2.6.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Block Attributes

CVE-2024-2729 Medium 2.6.6
CVE-2024-2729 Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE Stored Cross-Site Scripting

Otter Blocks <= 2.6.5 - Authenticated (Contributor+) Stored Cross-Site Scripting

CVE-2024-2841 Medium 2.6.6
CVE-2024-2841 Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE Stored Cross-Site Scripting

Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE <= 2.6.5 - Authenticated (Contributor+) Stored Cross-Site Scripting

Coverage Snapshot

What this page helps you verify fast

This hub clusters every indexed record for Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE so operators can confirm whether a disclosed issue maps to the installed slug, version range, and patch path.

Patch Visibility
12 records include a published patch path, leaving 0 with no listed safe release yet.
Severity Mix
0 critical and 2 high severity findings.
Recent CVEs
CVE-2026-2892, CVE-2025-55715 and CVE-2024-11219
Reference Workflow
Jump from the hub into the full report when you need remediation notes, exploit context, CVSS vectors, or source references.
Triage First

Open the records most likely to drive action

These recent records surface the CVE strings, patch cues, and direct report links most operators need first.

Known Vulnerabilities

Reports for Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE

Sorted by latest disclosure date so newly published issues surface first.

Plugin High Patched: Yes CVE-2026-2892
CVE-2026-2892: Otter Blocks <= 3.1.4 - Improper Authorization to Unauthenticated Purchase Verification Bypass via Forged Cookie

The Otter Blocks plugin for WordPress is vulnerable to Purchase Verification Bypass in all versions up to, and including, 3.1.4. This is due to the 'get_customer_data' method relying on an unsigned 'o_stripe_data' cookie to determine Stripe product ownership for unauthenticated u...

Published
Apr 29, 2026
Patched Release
3.1.5
Affected Versions
Versions up to 3.1.4
Next Step
Update to 3.1.5 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-55715
CVE-2025-55715: Otter - Gutenberg Block <= 3.1.0 - Unauthenticated Sensitive Information Exposure

The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.1.0. This makes it possible for unauthenticated attackers to extract sensitive user or configu...

Published
Aug 27, 2025
Patched Release
3.1.1
Affected Versions
Versions up to 3.1.0
Next Step
Update to 3.1.1 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-11219
CVE-2024-11219: Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE <= 3.0.6 - Unauthetnicated Path Traversal to Arbitrary Image View

The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 3.0.6 via the get_image function. This makes it possible for unauthenticated attackers to view arbitrary images...

Published
Nov 26, 2024
Patched Release
3.0.7
Affected Versions
Versions up to 3.0.6
Next Step
Update to 3.0.7 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-51671
CVE-2024-51671: Otter - Gutenberg Block <= 3.0.3 - Missing Authorization

The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.0.3. This makes it possible for authenticated attackers,...

Published
Nov 01, 2024
Patched Release
3.0.4
Affected Versions
Versions up to 3.0.3
Next Step
Update to 3.0.4 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-10367
CVE-2024-10367: Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE <= 3.0.4 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload

The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API SVG File uploads in all versions up to, and including, 3.0.4 due to insufficient input sanitization and output escaping. Thi...

Published
Oct 31, 2024
Patched Release
3.0.5
Affected Versions
Versions up to 3.0.4
Next Step
Update to 3.0.5 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-3725
CVE-2024-3725: Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE <= 2.6.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'titleTag'

The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Post Grid widget in all versions up to, and including, 2.6.9 due to insufficient input sanitization and output escaping...

Published
Apr 16, 2024
Patched Release
2.6.10
Affected Versions
Versions up to 2.6.9
Next Step
Update to 2.6.10 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-3344
CVE-2024-3344: Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE <= 2.6.8 - Authenticated (Author+) Limited File Upload to Stored Cross-Site Scripting

The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG file upload in all versions up to, and including, 2.6.8 due to insufficient input sanitization and output escaping. This makes it...

Published
Apr 10, 2024
Patched Release
2.6.9
Affected Versions
Versions up to 2.6.8
Next Step
Update to 2.6.9 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-3343
CVE-2024-3343: Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE <= 2.6.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Block Attributes

The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's block attributes in all versions up to, and including, 2.6.8 due to insufficient input sanitization and output escaping...

Published
Apr 10, 2024
Patched Release
2.6.9
Affected Versions
Versions up to 2.6.8
Next Step
Update to 2.6.9 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-2729
CVE-2024-2729: Otter Blocks <= 2.6.5 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via new post creation in all versions up to, and including, 2.6.5 due to insufficient input sanitization and output escaping. This makes...

Published
Mar 28, 2024
Patched Release
2.6.6
Affected Versions
Versions up to 2.6.5
Next Step
Update to 2.6.6 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-2841
CVE-2024-2841: Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE <= 2.6.5 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets in all versions up to, and including, 2.6.5 due to insufficient input sanitization and output escaping on user s...

Published
Mar 28, 2024
Patched Release
2.6.6
Affected Versions
Versions up to 2.6.5
Next Step
Update to 2.6.6 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-2226
CVE-2024-2226: Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE <= 2.6.4 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the id parameter in the google-map block in all versions up to, and including, 2.6.4 due to insufficient input sanitization and outpu...

Published
Mar 13, 2024
Patched Release
2.6.5
Affected Versions
Versions up to 2.6.4
Next Step
Update to 2.6.5 or newer if supported.
Plugin High Patched: Yes CVE-2023-2288
CVE-2023-2288: Otter - Gutenberg Blocks <= 2.2.5 - Authenticated (Author+) PHAR Deserialization

The Otter - Gutenberg Blocks plugin for WordPress is vulnerable to deserialization of untrusted input via the 'fallback' parameter in versions up to, and including 1.2.7. This makes it possible for authenticated attackers with author privileges to call files using a PHAR wrapper...

Published
May 02, 2023
Patched Release
2.2.6
Affected Versions
Versions up to 2.2.5
Next Step
Update to 2.2.6 or newer if supported.