Brainstormforce Spectra
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Brainstormforce Spectra.
By the Year
In 2026 there have been 4 vulnerabilities in Brainstormforce Spectra with an average score of 6.5 out of ten. Last year, in 2025 Spectra had 3 security vulnerabilities published. That is, 1 more vulnerability have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.38.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 4 | 6.45 |
| 2025 | 3 | 6.07 |
| 2024 | 15 | 5.98 |
| 2023 | 3 | 5.43 |
It may take a day or so for new Spectra vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Brainstormforce Spectra Security Vulnerabilities
Spectra Gutenberg Blocks WP Stored XSS <=2.19.28
CVE-2026-12900
6.4 - Medium
- July 20, 2026
The Spectra Gutenberg Blocks Website Builder for the Block Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `uagb/image` block in all versions up to, and including, 2.19.28 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
XSS
WordPress Spectra Gutenberg Blocks RCE up to v2.19.25 via block rendering
CVE-2026-7465
8.8 - High
- May 30, 2026
The Spectra Gutenberg Blocks Website Builder for the Block Editor plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.19.25. This makes it possible for authenticated attackers, with Contributor-level access and above, to execute code on the server. Exploitation requires a two-block payload embedded in post content: the first block registers a fake uagb/-prefixed block type with an attacker-specified render_callback, and the second block of the same fake type triggers invocation of that callback via call_user_func() during sequential block rendering in the same page request.
Improper Privilege Management
Spectra <=2.19.17 Missing Auth Vulnerability
CVE-2026-24982
5.3 - Medium
- February 03, 2026
Missing Authorization vulnerability in Brainstorm Force Spectra ultimate-addons-for-gutenberg allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Spectra: from n/a through <= 2.19.17.
AuthZ
Spectra Gutenberg Blocks WP Plugin 2.19.17 Info Disclosure via post excerpts
CVE-2026-0950
5.3 - Medium
- February 03, 2026
The Spectra Gutenberg Blocks Website Builder for the Block Editor plugin for WordPress is vulnerable to Information Disclosure in all versions up to, and including, 2.19.17. This is due to the plugin failing to check `post_password_required()` before rendering post excerpts in the `render_excerpt()` function and the `uagb_get_excerpt()` helper function. This makes it possible for unauthenticated attackers to read excerpts of password-protected posts by simply viewing any page that contains a Spectra Post Grid, Post Masonry, Post Carousel, or Post Timeline block.
Information Disclosure
Missing Auth in Brainstorm Force Spectra <=2.3.0
CVE-2023-23729
5.4 - Medium
- December 09, 2025
Missing Authorization vulnerability in Brainstorm Force Spectra allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Spectra: from n/a through 2.3.0.
AuthZ
Spectra Gutenberg Blocks 2.19.14: Stored XSS via Custom CSS
CVE-2025-11162
6.4 - Medium
- November 05, 2025
The Spectra Gutenberg Blocks Website Builder for the Block Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custom CSS in all versions up to, and including, 2.19.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
XSS
Spectra WordPress Gutenberg Blocks XSS via uagb – <2.19.0
CVE-2025-1784
6.4 - Medium
- March 26, 2025
The Spectra WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the uagb block in all versions up to, and including, 2.19.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
XSS
Brainstorm Force Spectra <2.3.0 Missing Auth Allows Unauthorized Access
CVE-2023-23834
4.3 - Medium
- December 09, 2024
Missing Authorization vulnerability in Brainstorm Force Spectra allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Spectra: from n/a through 2.3.0.
AuthZ
Missing Auth: Spectra <=2.3.0 misconfigured ACL
CVE-2023-23825
3.1 - Low
- December 09, 2024
Missing Authorization vulnerability in Brainstorm Force Spectra allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Spectra: from n/a through 2.3.0.
AuthZ
Stored XSS Vulnerability in Spectra WordPress Gutenberg Blocks Plugin
CVE-2024-10484
6.4 - Medium
- December 03, 2024
The Spectra WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'Team' widget in all versions up to, and including, 2.16.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
XSS
Missing Auth in Brainstorm Force Spectra 2.13.7 Access Control Vulnerability
CVE-2024-37517
8.8 - High
- November 01, 2024
Missing Authorization vulnerability in Brainstorm Force Spectra allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Spectra: from n/a through 2.13.7.
AuthZ
Brainstorm Force Spectra Stored XSS v2.14.1
CVE-2024-7590
- August 12, 2024
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm Force Spectra ultimate-addons-for-gutenberg allows DOM-Based XSS.This issue affects Spectra: from n/a through <= 2.14.1.
XSS
Missing Auth in Brainstorm Force Spectra (v<=2.6.6)
CVE-2023-36676
8.8 - High
- June 19, 2024
Missing Authorization vulnerability in Brainstorm Force Spectra.This issue affects Spectra: from n/a through 2.6.6.
AuthZ
BrainstormForce Spectra <=2.3.0 Injection (Content Spoofing/Phishing)
CVE-2023-23738
5.3 - Medium
- June 03, 2024
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Brainstorm Force Spectra allows Content Spoofing, Phishing.This issue affects Spectra: from n/a through 2.3.0.
Injection
Spectra < 2.3.0 XSS via Improper Script Tag Neutralization
CVE-2023-23735
5.3 - Medium
- June 03, 2024
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Brainstorm Force Spectra allows Code Injection.This issue affects Spectra: from n/a through 2.3.0.
Basic XSS
Spectra <=2.3.0 Auth Attempt Bypass (IAAT)
CVE-2023-23730
5.3 - Medium
- June 03, 2024
Improper Restriction of Excessive Authentication Attempts vulnerability in Brainstorm Force Spectra allows Functionality Bypass.This issue affects Spectra: from n/a through 2.3.0.
Improper Restriction of Excessive Authentication Attempts
Spectra WP Gutenberg Blocks <=2.13.0 XSS via block_id
CVE-2024-4366
6.4 - Medium
- May 24, 2024
The Spectra WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the block_id parameter in versions up to, and including, 2.13.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
XSS
XSS in Spectra Gutenberg Blocks <=2.12.8 via Testimonial Block
CVE-2024-1814
6.4 - Medium
- May 23, 2024
The Spectra WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Testimonial block in all versions up to, and including, 2.12.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
XSS
Spectra WP Gutenberg Blocks XSS in Image Gallery <=2.12.8
CVE-2024-1815
6.4 - Medium
- May 23, 2024
The Spectra WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Gallery block in all versions up to, and including, 2.12.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
XSS
Spectra WP Gutenberg Blocks v2.12.6 PT via get_block_default_attrs
CVE-2024-3107
4.3 - Medium
- May 02, 2024
The Spectra WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Path Traversal in versions up to, and including, 2.12.6 via the get_block_default_attributes function. This allows authenticated attackers, with contributor-level permissions and above, to read the contents of any files named attributes.php on the server, which can contain sensitive information.
Directory traversal
Spectra WP Gutenberg: Stored XSS via Custom CSS (2.10.3)
CVE-2023-6486
6.4 - Medium
- April 09, 2024
The Spectra WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custom CSS metabox in all versions up to and including 2.10.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
XSS
Brainstorm Force Spectra SSRF Vulnerability (v<=2.6.6)
CVE-2023-36679
6.5 - Medium
- March 28, 2024
Server-Side Request Forgery (SSRF) vulnerability in Brainstorm Force Spectra.This issue affects Spectra: from n/a through 2.6.6.
SSRF
Stored XSS in Spectra Gutenberg Blocks <=2.7.9
CVE-2023-49833
5.4 - Medium
- December 14, 2023
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm Force Spectra WordPress Gutenberg Blocks allows Stored XSS.This issue affects Spectra WordPress Gutenberg Blocks: from n/a through 2.7.9.
XSS
Ultimate Addons for Gutenberg <=1.14.7 Auth Settings Change via AJAX (Sub)
CVE-2020-36702
5.5 - Medium
- June 07, 2023
The Ultimate Addons for Gutenberg plugin for WordPress is vulnerable to Authenticated Settings Change in versions up to, and including, 1.14.7. This is due to missing capability checks on several AJAX actions. This makes it possible for authenticated attackers with subscriber+ roles to update the plugin's settings.
AuthZ
Spectra WP Plugin <=1.15.0 Stored XSS via Gutenberg blocks
CVE-2020-36656
5.4 - Medium
- February 21, 2023
The Spectra WordPress plugin before 1.15.0 does not sanitize user input as it reaches its style HTML attribute, allowing contributors to conduct stored XSS attacks via the plugin's Gutenberg blocks.
XSS
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Brainstormforce Spectra or by Brainstormforce? Click the Watch button to subscribe.