VK Block Patterns
VK Block Patterns has 2 disclosed vulnerabilities in the WordSec catalog, all reported in 2024; all 2 are fixed as of September 2026. Their average CVSS score is 4.8, and the most serious one scores 5.3 out of 10. 2024 was the busiest year with 2 disclosures.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (50%). Other recurring categories include Missing Authorization.
Every one of the 2 issues recorded for VK Block Patterns has a vendor fix available, so running the current release closes all known holes.
2 independent researchers contributed these findings, one record each. VK Block Patterns is installed on roughly 100,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.
CVE-2024-32826VK Block Patterns <= 1.31.0 - Missing Authorization
Read the full analysisVulnerability Records

VK Block Patterns
Author
Vektor,Inc.
When you activate this plugin that create new custom post type for custom block patterns. If you register custom patterns that you can select registered block patterns on edit screen.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C