CVE-2024-2369Cross-site Scripting in Coblocks

Severity
5.4MEDIUMNVD
EPSS
0.3%
top 42.70%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 2
Latest updateDec 27

Description

The Page Builder Gutenberg Blocks WordPress plugin before 3.1.7 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NExploitability: 2.3 | Impact: 2.7

Affected Packages1 packages

NVDgodaddy/coblocks< 3.1.7

🔴Vulnerability Details

2
GHSA
GHSA-wv8p-qvw7-q865: The Page Builder Gutenberg Blocks WordPress plugin before 32024-04-02
CVEList
Page Builder Gutenberg Blocks < 3.1.7 - Contributor+ Stored XSS2024-04-02

📋Vendor Advisories

1
Red Hat
kernel: iommufd: Fix out_fput in iommufd_fault_alloc()2024-12-27
CVE-2024-2369 — Cross-site Scripting in Coblocks | cvebase