CVE-2024-3239

May 14, 2024, 4:11 p.m.

Product(s) Impacted

Post Grid Gutenberg Blocks and WordPress Blog Plugin

  • before 4.0.2

Description

The Post Grid Gutenberg Blocks and WordPress Blog Plugin WordPress plugin before 4.0.2 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

Weaknesses

Date

Published: May 14, 2024, 3:40 p.m.

Last Modified: May 14, 2024, 4:11 p.m.

Status : Awaiting Analysis

CVE has been marked for Analysis. Normally once in this state the CVE will be analyzed by NVD staff within 24 hours.

More info

Source

contact@wpscan.com

References