brainstormforce Vulnerabilities and Affected Products
Vulnerabilities associated with Spectra Legacy – Gutenberg Blocks.
Products
Clear product- Spectra Gutenberg Blocks – Website Builder for the Block Editor11 vulnerabilities
- Ultimate Addons for Elementor10 vulnerabilities
- SureForms – Contact Form, Payment Form & Other Custom Form Builder7 vulnerabilities
- Ultimate Addons for Beaver Builder – Lite5 vulnerabilities
- CartFlows – Funnel Builder & Checkout Plugin for WooCommerce3 vulnerabilities
- Starter Templates – AI-Powered Templates for Elementor & Gutenberg3 vulnerabilities
- ultimate_addons_for_elementor3 vulnerabilities
- Astra2 vulnerabilities
- Custom Fonts – Host Your Fonts Locally2 vulnerabilities
- OttoKit: All-in-One Automation Platform2 vulnerabilities
- spectra2 vulnerabilities
- SureForms – Drag and Drop Form Builder for WordPress2 vulnerabilities
- convertplug1 vulnerability
- Import / Export Customizer Settings1 vulnerability
- Lightweight Sidebar Manager1 vulnerability
- Spectra Legacy – Gutenberg Blocks1 vulnerability
- spectra_pro1 vulnerability
- Starter Templates — Elementor, Gutenberg & Beaver Builder Templates1 vulnerability
- starter_templates1 vulnerability
- Surecart1 vulnerability
- SureDash – Community, Courses & Member Dashboard1 vulnerability
- SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz1 vulnerability
- SureForms – Drag & Drop Contact Form & Form Builder, Payment Form, Survey, Quiz & Calculator1 vulnerability
- SureMail – SMTP and Email Logs Plugin with Amazon SES, Postmark, and Other Providers1 vulnerability
- ultimate_addons_for_wpbakery_page_builder1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-12900MEDIUM | Spectra Gutenberg Blocks <= 2.19.28 - Authenticated (Contributor+) Stored Cross-Site Scripting via uagb/image BlockThe Spectra Gutenberg Blocks – Website Builder for the Block Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `uagb/image` block in all versions up to, and including, 2.19.28 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CWE-79Jul 20, 2026 | CVSS6.4v3.1 | EPSS0.187% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |