CVE-2025-11270

Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns <= 5.7.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'titleTag' attribute in all versions up to, and including, 5.7.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.


We have discovered 30,593 live websites that are affected by CVE-2025-11270.

Run a Free Instant Scan




Affected Software

Product  Essential Blocks
Category Wordpress Plugins
Vulnerable Domains30,593 live websites (100% of Essential Blocks install base)
Vulnerable Versions
  • from 0 through 5.7.1
Vulnerable Versions Count0 versions ( less than 0.1% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Oct 18, 2025
  • Updated - Oct 20, 2025

Credits

  • Rafshanzani Suhada (finder)

Website Distribution by Country

Number of websites using CVE-2025-11270
United States9,933 websites



Germany2,647 websites
France1,662 websites
Brazil1,278 websites
GB1,255 websites
India1,117 websites
Cyprus968 websites
Italy903 websites
Spain827 websites
Poland802 websites

Website Distribution by TLD

Number of websites using CVE-2025-11270
.com13,322 websites
.org2,245 websites
.de1,237 websites
.com.br1,086 websites
.fr803 websites
.it697 websites
.co.uk665 websites
.net653 websites
.nl608 websites
.pl581 websites

Websites affected by CVE-2025-11270

Top websites that are affected by CVE-2025-11270. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
**********.de Germany*,***
********.com United States*,***
***********.com United States*,***
************.com United States*,***
**************************.com United States**,***
****.org United States**,***
******.com United States**,***
*********.***.com United States**,***
******.com Canada**,***
*******.org Cyprus**,***
See full domain list

FAQ

CVE-2025-11270 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Essential Blocks
A total of 30,593 websites have been identified as vulnerable to CVE-2025-11270, based on global website indexing conducted by WebTechSurvey.
The Essential Blocks is affected by the CVE-2025-11270 vulnerability.
Essential Blocks versions up to and including 5.7.1 are vulnerable to CVE-2025-11270.