Spectra Legacy – Gutenberg Blocks

Spectra Legacy – Gutenberg Blocks has 30 disclosed vulnerabilities in the WordSec catalog, reported between 2020 and 2026; all 30 are fixed as of September 2026. Their average CVSS score is 5.9, and the most serious one scores 8.8 out of 10. Severity breakdown: 0 critical and 2 high. 2023 was the busiest year with 12 disclosures.

The most common weakness is Cross-Site Scripting, behind 12 of the records (40%). Other recurring categories include Missing Authorization, Cross-Site Request Forgery (CSRF).

Every one of the 30 issues recorded for Spectra Legacy – Gutenberg Blocks has a vendor fix available, so running the current release closes all known holes.

18 independent researchers contributed these findings, most of them (4) reported by Dave Jong. Spectra Legacy – Gutenberg Blocks is installed on roughly 1,000,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.

01234567891013.06.2018Today30.03.20205.5Spectra – WordPress Gutenberg Blocks <= 1.14.7 - Missing Authorization CVSS 5.5 · 30.03.202031.05.20226.1Spectra – WordPress Gutenberg Blocks <= 1.25.5 - Reflected Cross-Site Scripting CVSS 6.1 · 31.05.202223.01.20236.5Spectra – WordPress Gutenberg Blocks <= 2.3.1 - HTML Injection in Emails CVSS 6.5 · 23.01.20235.4Spectra – WordPress Gutenberg Blocks <= 2.3.1 - Missing Authorization to Captcha Setting Update CVSS 5.4 · 23.01.20235.4Spectra – WordPress Gutenberg Blocks <= 2.3.1 - Cross-Site Request Forgery to WPForm/Blocks Import CVSS 5.4 · 23.01.20235.3Spectra – WordPress Gutenberg Blocks <= 2.3.1 - Email Spoofing CVSS 5.3 · 23.01.20235.3Spectra – WordPress Gutenberg Blocks <= 2.3.1 - Captcha Bypass CVSS 5.3 · 23.01.202324.01.20236.4Spectra – WordPress Gutenberg Blocks <= 1.14.11 - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 6.4 · 24.01.202325.01.20236.3Spectra – WordPress Gutenberg Blocks <= 2.3.1 - Missing Authorization Checks CVSS 6.3 · 25.01.20236.3Spectra – WordPress Gutenberg Blocks <= 2.3.1 - Cross-Site Request Forgery to Plugin Activation CVSS 6.3 · 25.01.202314.07.20234.3Spectra <= 2.6.6 - Missing Authorization CVSS 4.3 · 14.07.20236.4Spectra <= 2.6.6 - Authenticated (Contributor+) Server-Side Request Forgery in template_importer CVSS 6.4 · 14.07.20238.5Spectra <= 2.6.6 - Authenticated (Contributor+) Server-Side Request Forgery in import_wpforms CVSS 8.5 · 14.07.202305.12.20236.4Spectra <= 2.7.9 - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 6.4 · 05.12.202303.04.20246.4Spectra – WordPress Gutenberg Blocks <= 2.10.3 - Authenticated(Contributor+) Cross-Site Scripting via Custom CSS CVSS 6.4 · 03.04.202426.04.20244.3Spectra – WordPress Gutenberg Blocks <= 2.12.6 - Authenticated (Contributor+) Path Traversal CVSS 4.3 · 26.04.202422.05.20246.4Spectra – WordPress Gutenberg Blocks <= 2.12.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Testimonial Block CVSS 6.4 · 22.05.20246.4Spectra – WordPress Gutenberg Blocks <= 2.12.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image Gallery Block CVSS 6.4 · 22.05.202423.05.20246.4Spectra – WordPress Gutenberg Blocks <= 2.13.0 - Authenticated (Author+) Stored Cross-Site Scripting CVSS 6.4 · 23.05.202405.07.20244.3Spectra <= 2.13.7 - Missing Authorization via generate_ai_content CVSS 4.3 · 05.07.202407.08.20246.4Spectra – WordPress Gutenberg Blocks <= 2.15.0 - Authenticated (Contributor+) Stored Cross-site Scripting CVSS 6.4 · 07.08.202402.12.20246.4Spectra – WordPress Gutenberg Blocks <= 2.16.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Team Widget CVSS 6.4 · 02.12.202425.03.20256.4Spectra – WordPress Gutenberg Blocks <= 2.19.0 - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 6.4 · 25.03.202504.11.20256.4Spectra <= 2.19.14 - Authenticated (Contributor+) Stored Cross-Site Scripting via Custom CSS CVSS 6.4 · 04.11.202517.01.20265.3Spectra <= 2.19.17 - Missing Authorization CVSS 5.3 · 17.01.202602.02.20265.3Spectra Gutenberg Blocks <= 2.19.17 - Unauthenticated Information Disclosure in Sensitive Data CVSS 5.3 · 02.02.202627.03.20264.3Spectra <= 2.19.22 - Missing Authorization CVSS 4.3 · 27.03.202629.05.20268.8Spectra Gutenberg Blocks <= 2.19.25 - Authenticated (Contributor+) Remote Code Execution via Arbitrary PHP Function Call via Block Attributes CVSS 8.8 · 29.05.202620.07.20264.3Spectra Legacy – Gutenberg Blocks < 2.20.0 - Authenticated (Contributor+) CSS Injection CVSS 4.3 · 20.07.20266.4Spectra Gutenberg Blocks <= 2.19.28 - Authenticated (Contributor+) Stored Cross-Site Scripting via uagb/image Block CVSS 6.4 · 20.07.2026

Strategic Overview

Avg CVSSMedium
5.9/ 10
Patch Coverage100%
Open

0

Fixed

30

Get automatic notifications for all Spectra Legacy – Gutenberg Blocks vulnerabilities before they are exploited.

Highest severity on recordCVSS 8.8CVE-2026-7465

Spectra Gutenberg Blocks <= 2.19.25 - Authenticated (Contributor+) Remote Code Execution via Arbitrary PHP Function Call via Block Attributes

Read the full analysis

Vulnerability Records

30 records
2026-07-20 09:16CVE-2026-12900
6.4
Medium
theviper17yYes
2026-07-20 00:00CVE-2026-10827
4.3
Medium
Muni Nitish Kumar YaddalaYes
2026-05-29 20:27CVE-2026-7465
8.8
High
kai63001Yes
2026-03-27 00:00CVE-2026-42648
4.3
Medium
Trương Hữu Phúc (truonghuuphuc)Yes
2026-02-02 16:58CVE-2026-0950
5.3
Medium
johskaYes
2026-01-17 00:00CVE-2026-24982
5.3
Medium
Bao - BlueRockYes
2025-11-04 16:25CVE-2025-11162
6.4
Medium
Muhammad Yudha - DJYes
2025-03-25 16:21CVE-2025-1784
6.4
Medium
Peter ThaleikisYes
2024-12-02 16:32CVE-2024-10484
6.4
Medium
zer0gh0stYes
2024-08-07 00:00CVE-2024-7590
6.4
Medium
João Pedro Soares de AlcântaraYes
Showing 1–10 of 30 reports
Spectra Legacy – Gutenberg Blocks banner
Latestv2.20.3

Spectra Legacy – Gutenberg Blocks

Brainstorm Force

Author

Brainstorm Force

4.7(1,870)
94/100
Last Updated
2026-08-26 (18d ago)
Active Installs
1,000,000+
Downloads
43,446,981
Requires WP
5.6+
Requires PHP
7.4+
Tested up to
WP 7.1
Created
2018-06-13 (8y ago)

This plugin was previously called Spectra. It’s now Spectra Legacy. Nothing on your website has changed. Your blocks, pages, settings, and content all continue to work exactly as they did before. There’s nothing to migrate and nothing to configure. Spectra Legacy vs. Spectra Blocks We’ve split Spectra into two products. Spectra Legacy is this plugin — built for existing Spectra users. It receives security and compatibility updates and full support, but no new features. Spectra Blocks is a new, separate plugin where all new feature development happens, aimed at new installs and anyone who wants ongoing additions. If you’re already using this plugin, no action is needed; installing Spectra Blocks is entirely optional whenever you’re ready. If you’re already using this plugin, you don’t need to do anything. If you want new features as they’re released, you can install Spectra Blocks separately, whenever you’re ready. There’s no deadline and no required migration. What’s included Spectra Legacy includes the full block library your site is already built on: layout tools, content and post blocks, form and SEO blocks, social blocks, and site tools like Popup Builder and Coming Soon mode. Blocks included Core — Container, Heading, Image, Icon, Buttons, Info Box, Call To Action, Countdown Content — Sliders, Content Timeline, Google Maps, Inline Notices, Tabs, Taxonomy List, Price List (Loop Builder in Spectra Pro Legacy) Post — Counter, Modal Popup, Post Carousel, Post Grid, Post Timeline Social — Instagram Feed, Blockquote, Social Share, Team, Testimonials Forms — Contact form, newsletter signup, suggestion form, reCAPTCHA (registration/login forms in Spectra Pro Legacy) SEO — FAQ, How-To, Review, Table of Contents Dynamic content — Archive feed filtering by date, author, category, and post type Site tools — Popup Builder, Coming Soon mode, block animations, local Google Fonts, global styling defaults About the AI block The AI block previously included in this plugin is now called ZipAI. It still works in Spectra Legacy for compatibility. New AI features are being built in Spectra Blocks going forward. Compatibility Works with most standard WordPress themes, including Spectra One, Astra, Blocksy, and GeneratePress. Compatible with common plugins including WooCommerce, SureCart, Gravity Forms, LearnDash, MemberPress, and Yoast SEO. See our documentation for the full compatibility list. Support & community Spectra Legacy is actively maintained — security patches, compatibility updates, and support all continue. This plugin is not deprecated. Support forum: use the Support tab on this page Documentation: wpspectra.com/docs Facebook Group: Web Creators by Astra Facebook: Spectra X (Twitter): @wpspectra Contribute Spectra is open source. Browse the code or contribute on GitHub: brainstormforce/wp-spectra Credits Our external packages use Rating Star Component that are distributed under the terms of the ISC. While Slick, Lottie and Striptags is distributed under the terms of the MIT. Additionally, we incorporate FontAwesome v6 under the CC BY 4.0 License, and dnd kit licensed under the MIT License.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C