Today > vulnerabilities   -   You can now download lists of IOCs here!

CVE-2024-4305

June 17, 2024, 12:42 p.m.

Product(s) Impacted

Post Grid Gutenberg Blocks and WordPress Blog Plugin

  • before 4.1.0

Description

The Post Grid Gutenberg Blocks and WordPress Blog Plugin WordPress plugin before 4.1.0 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

Weaknesses

Date

Published: June 17, 2024, 6:15 a.m.

Last Modified: June 17, 2024, 12:42 p.m.

Status : Awaiting Analysis

CVE has been recently published to the CVE List and has been received by the NVD.

More info

Source

contact@wpscan.com

References

https://wpscan.com/ contact@wpscan.com