CVE-2021-24634: Recipe Card Blocks < 2.8.3 - Contributor+ Stored Cross-Site Scripting
The Recipe Card Blocks by WPZOOM WordPress plugin before 2.8.3 does not properly sanitise or escape some of the properties of the Recipe Card Block (such as ingredientsLayout, iconSet, steps, ingredients, recipeTitle, or settings), which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-24634?
CVE-2021-24634 is classified as a medium severity vulnerability impacting the Recipe Card Blocks by WPZOOM.
How do I fix CVE-2021-24634?
To fix CVE-2021-24634, update the Recipe Card Blocks for Gutenberg & Elementor plugin to version 2.8.3 or later.
Who is affected by CVE-2021-24634?
Users of the Recipe Card Blocks by WPZOOM plugin prior to version 2.8.3 are affected by CVE-2021-24634.
What are the risks associated with CVE-2021-24634?
CVE-2021-24634 could allow low-privilege users to execute unauthorized actions due to improper sanitization of plugin properties.
Is there a patch available for CVE-2021-24634?
Yes, a patch is available in version 2.8.3 of the Recipe Card Blocks by WPZOOM plugin.