CVE-2026-12900

Spectra Gutenberg Blocks <= 2.19.28 - Authenticated (Contributor+) Stored Cross-Site Scripting via uagb/image Block

The Spectra Gutenberg Blocks – Website Builder for the Block Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `uagb/image` block in all versions up to, and including, 2.19.28 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.


We have discovered 65,586 live websites that are affected by CVE-2026-12900.

Run a Free Instant Scan




Affected Software

Product  Spectra
Category Wordpress Plugins
Vulnerable Domains65,586 live websites (91% of Spectra install base)
Vulnerable Versions
  • from 0 through 2.19.28
Vulnerable Versions Count183 versions ( 99% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Jul 20, 2026
  • Updated - Jul 22, 2026

Credits

  • theviper17y (finder)

Website Distribution by Country

Number of websites using CVE-2026-12900
United States20,212 websites



Germany8,547 websites
France4,674 websites
GB2,764 websites
Cyprus2,649 websites
Spain2,308 websites
Netherlands1,952 websites
Poland1,944 websites
Italy1,793 websites
Canada1,412 websites

Website Distribution by TLD

Number of websites using CVE-2026-12900
.com28,063 websites
.de4,913 websites
.org3,805 websites
.fr2,666 websites
.nl1,791 websites
.net1,672 websites
.co.uk1,593 websites
.pl1,478 websites
.it1,347 websites
.es1,136 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-12900

Top websites that are affected by CVE-2026-12900. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*********.com Austria*,***
*****.com United States**,***
*********************.com United States**,***
**********.com Cyprus**,***
********.com United States**,***
*******.com United States**,***
****************.com United States**,***
***.*******.com United States**,***
*****.co **,***
***.fi Finland**,***
See full domain list

FAQ

CVE-2026-12900 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Spectra
A total of 65,586 websites have been identified as vulnerable to CVE-2026-12900, based on global website indexing conducted by WebTechSurvey.
The Spectra is affected by the CVE-2026-12900 vulnerability.
Spectra versions up to and including 2.19.28 are vulnerable to CVE-2026-12900.