The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'titleTag' attribute in all versions up to, and including, 5.7.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
We have discovered 30,593 live websites that are affected by CVE-2025-11270.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 30,593 live websites (100% of Essential Blocks install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 0 versions ( less than 0.1% of all versions) |
| 9,933 websites | |
| 2,647 websites | |
| 1,662 websites | |
| 1,278 websites | |
| 1,255 websites | |
| 1,117 websites | |
| 968 websites | |
| 903 websites | |
| 827 websites | |
| 802 websites |
| .com | 13,322 websites |
| .org | 2,245 websites |
| .de | 1,237 websites |
| .com.br | 1,086 websites |
| .fr | 803 websites |
| .it | 697 websites |
| .co.uk | 665 websites |
| .net | 653 websites |
| .nl | 608 websites |
| .pl | 581 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| **********.de | *,*** | ||
| ********.com | *,*** | ||
| ***********.com | *,*** | ||
| ************.com | *,*** | ||
| **************************.com | **,*** | ||
| ****.org | **,*** | ||
| ******.com | **,*** | ||
| *********.***.com | **,*** | ||
| ******.com | **,*** | ||
| *******.org | **,*** |
FAQ