Spectra Brainstormforce Spectra

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Brainstormforce Spectra.

By the Year

In 2026 there have been 4 vulnerabilities in Brainstormforce Spectra with an average score of 6.5 out of ten. Last year, in 2025 Spectra had 3 security vulnerabilities published. That is, 1 more vulnerability have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.38.




Year Vulnerabilities Average Score
2026 4 6.45
2025 3 6.07
2024 15 5.98
2023 3 5.43

It may take a day or so for new Spectra vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Brainstormforce Spectra Security Vulnerabilities

Spectra Gutenberg Blocks WP Stored XSS <=2.19.28
CVE-2026-12900 6.4 - Medium - July 20, 2026

The Spectra Gutenberg Blocks Website Builder for the Block Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `uagb/image` block in all versions up to, and including, 2.19.28 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

XSS

WordPress Spectra Gutenberg Blocks RCE up to v2.19.25 via block rendering
CVE-2026-7465 8.8 - High - May 30, 2026

The Spectra Gutenberg Blocks Website Builder for the Block Editor plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.19.25. This makes it possible for authenticated attackers, with Contributor-level access and above, to execute code on the server. Exploitation requires a two-block payload embedded in post content: the first block registers a fake uagb/-prefixed block type with an attacker-specified render_callback, and the second block of the same fake type triggers invocation of that callback via call_user_func() during sequential block rendering in the same page request.

Improper Privilege Management

Spectra <=2.19.17 Missing Auth Vulnerability
CVE-2026-24982 5.3 - Medium - February 03, 2026

Missing Authorization vulnerability in Brainstorm Force Spectra ultimate-addons-for-gutenberg allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Spectra: from n/a through <= 2.19.17.

AuthZ

Spectra Gutenberg Blocks WP Plugin 2.19.17 Info Disclosure via post excerpts
CVE-2026-0950 5.3 - Medium - February 03, 2026

The Spectra Gutenberg Blocks Website Builder for the Block Editor plugin for WordPress is vulnerable to Information Disclosure in all versions up to, and including, 2.19.17. This is due to the plugin failing to check `post_password_required()` before rendering post excerpts in the `render_excerpt()` function and the `uagb_get_excerpt()` helper function. This makes it possible for unauthenticated attackers to read excerpts of password-protected posts by simply viewing any page that contains a Spectra Post Grid, Post Masonry, Post Carousel, or Post Timeline block.

Information Disclosure

Missing Auth in Brainstorm Force Spectra <=2.3.0
CVE-2023-23729 5.4 - Medium - December 09, 2025

Missing Authorization vulnerability in Brainstorm Force Spectra allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Spectra: from n/a through 2.3.0.

AuthZ

Spectra Gutenberg Blocks 2.19.14: Stored XSS via Custom CSS
CVE-2025-11162 6.4 - Medium - November 05, 2025

The Spectra Gutenberg Blocks Website Builder for the Block Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custom CSS in all versions up to, and including, 2.19.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

XSS

Spectra WordPress Gutenberg Blocks XSS via uagb – <2.19.0
CVE-2025-1784 6.4 - Medium - March 26, 2025

The Spectra WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the uagb block in all versions up to, and including, 2.19.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

XSS

Brainstorm Force Spectra <2.3.0 Missing Auth Allows Unauthorized Access
CVE-2023-23834 4.3 - Medium - December 09, 2024

Missing Authorization vulnerability in Brainstorm Force Spectra allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Spectra: from n/a through 2.3.0.

AuthZ

Missing Auth: Spectra <=2.3.0 misconfigured ACL
CVE-2023-23825 3.1 - Low - December 09, 2024

Missing Authorization vulnerability in Brainstorm Force Spectra allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Spectra: from n/a through 2.3.0.

AuthZ

Stored XSS Vulnerability in Spectra WordPress Gutenberg Blocks Plugin
CVE-2024-10484 6.4 - Medium - December 03, 2024

The Spectra WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'Team' widget in all versions up to, and including, 2.16.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

XSS

Missing Auth in Brainstorm Force Spectra 2.13.7 Access Control Vulnerability
CVE-2024-37517 8.8 - High - November 01, 2024

Missing Authorization vulnerability in Brainstorm Force Spectra allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Spectra: from n/a through 2.13.7.

AuthZ

Brainstorm Force Spectra Stored XSS v2.14.1
CVE-2024-7590 - August 12, 2024

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm Force Spectra ultimate-addons-for-gutenberg allows DOM-Based XSS.This issue affects Spectra: from n/a through <= 2.14.1.

XSS

Missing Auth in Brainstorm Force Spectra (v<=2.6.6)
CVE-2023-36676 8.8 - High - June 19, 2024

Missing Authorization vulnerability in Brainstorm Force Spectra.This issue affects Spectra: from n/a through 2.6.6.

AuthZ

BrainstormForce Spectra <=2.3.0 Injection (Content Spoofing/Phishing)
CVE-2023-23738 5.3 - Medium - June 03, 2024

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Brainstorm Force Spectra allows Content Spoofing, Phishing.This issue affects Spectra: from n/a through 2.3.0.

Injection

Spectra < 2.3.0 XSS via Improper Script Tag Neutralization
CVE-2023-23735 5.3 - Medium - June 03, 2024

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Brainstorm Force Spectra allows Code Injection.This issue affects Spectra: from n/a through 2.3.0.

Basic XSS

Spectra <=2.3.0 Auth Attempt Bypass (IAAT)
CVE-2023-23730 5.3 - Medium - June 03, 2024

Improper Restriction of Excessive Authentication Attempts vulnerability in Brainstorm Force Spectra allows Functionality Bypass.This issue affects Spectra: from n/a through 2.3.0.

Improper Restriction of Excessive Authentication Attempts

Spectra WP Gutenberg Blocks <=2.13.0 XSS via block_id
CVE-2024-4366 6.4 - Medium - May 24, 2024

The Spectra WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the block_id parameter in versions up to, and including, 2.13.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

XSS

XSS in Spectra Gutenberg Blocks <=2.12.8 via Testimonial Block
CVE-2024-1814 6.4 - Medium - May 23, 2024

The Spectra WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Testimonial block in all versions up to, and including, 2.12.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

XSS

Spectra WP Gutenberg Blocks XSS in Image Gallery <=2.12.8
CVE-2024-1815 6.4 - Medium - May 23, 2024

The Spectra WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Gallery block in all versions up to, and including, 2.12.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

XSS

Spectra WP Gutenberg Blocks v2.12.6 PT via get_block_default_attrs
CVE-2024-3107 4.3 - Medium - May 02, 2024

The Spectra WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Path Traversal in versions up to, and including, 2.12.6 via the get_block_default_attributes function. This allows authenticated attackers, with contributor-level permissions and above, to read the contents of any files named attributes.php on the server, which can contain sensitive information.

Directory traversal

Spectra WP Gutenberg: Stored XSS via Custom CSS (2.10.3)
CVE-2023-6486 6.4 - Medium - April 09, 2024

The Spectra WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custom CSS metabox in all versions up to and including 2.10.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

XSS

Brainstorm Force Spectra SSRF Vulnerability (v<=2.6.6)
CVE-2023-36679 6.5 - Medium - March 28, 2024

Server-Side Request Forgery (SSRF) vulnerability in Brainstorm Force Spectra.This issue affects Spectra: from n/a through 2.6.6.

SSRF

Stored XSS in Spectra Gutenberg Blocks <=2.7.9
CVE-2023-49833 5.4 - Medium - December 14, 2023

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm Force Spectra WordPress Gutenberg Blocks allows Stored XSS.This issue affects Spectra WordPress Gutenberg Blocks: from n/a through 2.7.9.

XSS

Ultimate Addons for Gutenberg <=1.14.7 Auth Settings Change via AJAX (Sub)
CVE-2020-36702 5.5 - Medium - June 07, 2023

The Ultimate Addons for Gutenberg plugin for WordPress is vulnerable to Authenticated Settings Change in versions up to, and including, 1.14.7. This is due to missing capability checks on several AJAX actions. This makes it possible for authenticated attackers with subscriber+ roles to update the plugin's settings.

AuthZ

Spectra WP Plugin <=1.15.0 Stored XSS via Gutenberg blocks
CVE-2020-36656 5.4 - Medium - February 21, 2023

The Spectra WordPress plugin before 1.15.0 does not sanitize user input as it reaches its style HTML attribute, allowing contributors to conduct stored XSS attacks via the plugin's Gutenberg blocks.

XSS

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Brainstormforce Spectra or by Brainstormforce? Click the Watch button to subscribe.

subscribe