MEDIUM
PostX < 4.0.2 - Contributor+ Stored XSS
Published May 13, 2024
5.4
MEDIUMCVSS 3.1
EPSS 0.42%
Description
The Post Grid Gutenberg Blocks and WordPress Blog Plugin WordPress plugin before 4.0.2 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
Affected products
- Vendor n/a Product Post Grid Gutenberg Blocks and WordPress Blog Plugin Defaultunaffected
Affected
- ≥ 0, < 4.0.2
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| n/a | Post Grid Gutenberg Blocks and WordPress Blog Plugin | unaffected | Affected
|
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-31831 Advisory
- https://wpscan.com/vulnerability/dfa1421b-41b0-4b25-95ef-0843103e1f5e/ exploitvdb-entrytechnical-descriptionThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-31831 | Advisory | |
| https://wpscan.com/vulnerability/dfa1421b-41b0-4b25-95ef-0843103e1f5e/ | exploitvdb-entrytechnical-descriptionThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner WPScan
Published May 13, 2024
Updated Nov 1, 2024
Reserved Apr 2, 2024
Link CVE-2024-3239
CISA Vulnrichment
Updated May 13, 2024
Red Hat
No data
GitHub
No data