CVE-2024-11219: Themeisle Otter Blocks
High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.
The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 3.0.6 via the get_image function. This makes it possible for unauthenticated attackers to view arbitrary images on the server, which can contain sensitive information.
Affected products
- Themeisle Otter Blocks: before 3.0.7 (fixed in 3.0.7)
Published 2024-11-27. Last modified 2026-06-17.