CVE-2025-11361

Essential Blocks <= 5.7.1 - Authenticated (Author+) Server-Side Request Forgery

The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5.7.1 via the eb_save_ai_generated_image function. This makes it possible for authenticated attackers, with Author-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.


We have discovered 30,593 live websites that are affected by CVE-2025-11361.

Run a Free Instant Scan




Affected Software

Product  Essential Blocks
Category Wordpress Plugins
Vulnerable Domains30,593 live websites (100% of Essential Blocks install base)
Vulnerable Versions
  • from 0 through 5.7.1
Vulnerable Versions Count0 versions ( less than 0.1% of all versions)


Common Weakness Enumeration

CWE-918 Server-Side Request Forgery (SSRF)



Details

  • Published - Oct 18, 2025
  • Updated - Oct 20, 2025

Credits

  • Dmitrii Ignatyev (finder)

Website Distribution by Country

Number of websites using CVE-2025-11361
United States9,933 websites



Germany2,647 websites
France1,662 websites
Brazil1,278 websites
GB1,255 websites
India1,117 websites
Cyprus968 websites
Italy903 websites
Spain827 websites
Poland802 websites

Website Distribution by TLD

Number of websites using CVE-2025-11361
.com13,322 websites
.org2,245 websites
.de1,237 websites
.com.br1,086 websites
.fr803 websites
.it697 websites
.co.uk665 websites
.net653 websites
.nl608 websites
.pl581 websites

Websites affected by CVE-2025-11361

Top websites that are affected by CVE-2025-11361. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
**********.de Germany*,***
********.com United States*,***
***********.com United States*,***
************.com United States*,***
**************************.com United States**,***
****.org United States**,***
******.com United States**,***
*********.***.com United States**,***
******.com Canada**,***
*******.org Cyprus**,***
See full domain list

FAQ

CVE-2025-11361 is Server-Side Request Forgery (SSRF) in Essential Blocks
A total of 30,593 websites have been identified as vulnerable to CVE-2025-11361, based on global website indexing conducted by WebTechSurvey.
The Essential Blocks is affected by the CVE-2025-11361 vulnerability.
Essential Blocks versions up to and including 5.7.1 are vulnerable to CVE-2025-11361.