Nova Blocks by Pixelgrade

Nova Blocks by Pixelgrade has 3 disclosed vulnerabilities in the WordSec catalog, reported between 2024 and 2026; all 3 are fixed as of September 2026. Their average CVSS score is 6.4, and the most serious one scores 6.4 out of 10.

The most common weakness is Cross-Site Scripting, behind 3 of the records (100%).

Every one of the 3 issues recorded for Nova Blocks by Pixelgrade has a vendor fix available, so running the current release closes all known holes.

3 independent researchers contributed these findings, one record each. Nova Blocks by Pixelgrade is installed on roughly 800 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.

Strategic Overview

Avg CVSSMedium
6.4/ 10
Patch Coverage100%
Open

0

Fixed

3

Get automatic notifications for all Nova Blocks by Pixelgrade vulnerabilities before they are exploited.

Highest severity on recordCVSS 6.4CVE-2026-24528

Nova Blocks <= 2.1.9 - Authenticated (Contributor+) Stored Cross-Site Scripting

Read the full analysis

Vulnerability Records

3 records
Nova Blocks by Pixelgrade banner
Latestv2.6.6

Nova Blocks by Pixelgrade

pixelgrade

Author

pixelgrade

0.0(0)
0/100
Last Updated
2026-09-01 (11d ago)
Active Installs
800+
Downloads
49,899
Requires WP
7.0+
Requires PHP
7.4+
Tested up to
WP 7.1
Created
2019-07-25 (7y ago)

Nova Blocks is a collection of distinctive Gutenberg blocks, committed to making your site shine like a newborn star. It is taking a design-driven approach to help you made the right decisions and showcase your content in the best shape. Positioning Clear and obvious, exciting and not afraid to take risks, distinctive, forward thinking. Obvious, not confusing Exciting, not dull Distinctive, not common Principles Decisions not options Purpose-driven Distinctive Cross-themes oriented Tested with the following WordPress themes: Julia LT by Pixelgrade Rosa LT by Pixelgrade Felt LT by Pixelgrade Twenty Nineteen by WordPress team Storefront by Automattic Osteria by Pixelgrade Made with love by Pixelgrade Privacy & External Services Nova Blocks relies on one external service to deliver its curated block-pattern library. Pixelgrade Cloud (cloud.pixelgrade.com) To provide curated block patterns in the editor inserter, the plugin fetches block-pattern assets from Pixelgrade Cloud. This request is made from WordPress admin/editor contexts, not from ordinary frontend page loads, and the response is cached locally. When fetching block patterns, the plugin sends: your site URL, whether the site uses SSL, your WordPress version, the Nova Blocks version, the Style Manager version when present, and your active theme’s slug, stylesheet slug, name, URI, version, and text domain. No personal data about your site’s visitors is sent or collected, and the plugin does not load any tracking or analytics scripts for this feature. Service: Pixelgrade Cloud Provider: Pixelgrade — https://pixelgrade.com Privacy Policy: https://pixelgrade.com/privacy/ Contributing The proposed value of Open Source is that by freely sharing the code with the community, others can use, improve and contribute back to it. It’s great if you’re willing to use your skills, knowledge, and experience to help further refine this project with your own improvements. We really appreciate it and you’re 💯 welcome to submit an issue or pull request on any topic. How can you help? Discovered an issue? Please report it here. Fixed a bug? Send a pull request. Need a feature? Propose it here. Have you made something great? Share it with us. Translations You can translate Nova Blocks on translate.wordpress.org. Credits Unless otherwise specified, all the plugins files, scripts and images are licensed under GNU General Public License v2 or later. The Nova Blocks plugin bundles the following third-party resources: jQuery Bully plugin Copyright (c) 2016 Pixelgrade – License: MIT jQuery Slick plugin Copyright (c) 2017 Ken Wheeler – License: MIT jQuery Velocity plugin Copyright (c) 2014-2017 Julian Shapiro – License: MIT JS Cookie Copyright (c) 2018 Klaus Hartl, Fagner Brack, GitHub Contributors – License: MIT

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C