Smart Blocks – WordPress Gutenberg Blocks

Smart Blocks – WordPress Gutenberg Blocks has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2024 and 2025; all 2 are fixed as of September 2026. Their average CVSS score is 5.3, and the most serious one scores 6.4 out of 10.

The most common weakness is Cross-Site Scripting, behind 1 of the records (50%). Other recurring categories include Missing Authorization.

Every one of the 2 issues recorded for Smart Blocks – WordPress Gutenberg Blocks has a vendor fix available, so running the current release closes all known holes.

2 independent researchers contributed these findings, one record each. Smart Blocks – WordPress Gutenberg Blocks is installed on roughly 1,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.

Strategic Overview

Avg CVSSMedium
5.3/ 10
Patch Coverage100%
Open

0

Fixed

2

Get automatic notifications for all Smart Blocks – WordPress Gutenberg Blocks vulnerabilities before they are exploited.

Highest severity on recordCVSS 6.4CVE-2024-49270

Smart Blocks <= 2.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

Read the full analysis

Vulnerability Records

2 records
Smart Blocks – WordPress Gutenberg Blocks banner
Latestv2.8

Smart Blocks – WordPress Gutenberg Blocks

hashthemes

Author

hashthemes

5.0(3)
100/100
Last Updated
2025-12-07 (9mo ago)
Active Installs
1,000+
Downloads
35,386
Requires WP
6.3+
Requires PHP
7.2+
Tested up to
WP 6.9.7
Created
2022-07-01 (4y ago)

SmartBlocks is a light weight WordPress Plugin that adds advanced and powerful Gutenberg Blocks and opens infinite possibilities to the WordPress Gutenberg editor for anyone to create the website of their own imagination in no time without touching a single line of code. SmartBlocks has 20+ unique and beautifully designed Gutenberg blocks that extend the library of existing WordPress blocks. The plugin works with any WordPress theme and is compatible with any other WordPress plugins.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C