Zypento Blocks
Zypento Blocks has one disclosed vulnerability in the WordSec catalog, all reported in 2026; it remains unpatched as of August 2026. Their average CVSS score is 6.4, and the most serious one scores 6.4 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).
The one issue recorded for Zypento Blocks has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2026.
All of these findings were reported by Athiwat Tiprasaharn (Jitlada). The current release is tested up to WordPress 6.9.7.
CVE-2026-5820Zypento Blocks <= 1.0.6 - Authenticated (Author+) Stored Cross-Site Scripting via Table of Contents Block
Read the full analysisVulnerability Records
Zypento Blocks
Author
sproutient
Gutenberg block library with WooCommerce product collection, slider. countdown timer and Table of Contents. CSS/JS source Unminified CSS/JS are in assets/css/src and assets/js/src. GitHub https://github.com/sproutient/zypento-blocks Clone the repository, Then to compile css/js from source, run ‘composer install’ once and whenever you want to compile, run ‘composer create-scripts’
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C