CVE-2024-10637: Kadence Blocks < 3.2.54 - Admin+ Stored XSS
The Gutenberg Blocks with AI by Kadence WP WordPress plugin before 3.2.54 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-10637?
CVE-2024-10637 has a medium severity rating due to its potential for allowing stored cross-site scripting attacks.
How do I fix CVE-2024-10637?
To fix CVE-2024-10637, update the Gutenberg Blocks with AI by Kadence WP plugin to version 3.2.54 or later.
Who is affected by CVE-2024-10637?
CVE-2024-10637 affects users with the contributor role and above who utilize the affected version of the plugin.
What type of vulnerability is CVE-2024-10637?
CVE-2024-10637 is a stored cross-site scripting (XSS) vulnerability.
What versions of the software are affected by CVE-2024-10637?
CVE-2024-10637 affects versions of the Gutenberg Blocks with AI by Kadence WP plugin prior to 3.2.54.