First published: Thu Dec 12 2024(Updated: )
The Gutenberg Blocks with AI by Kadence WP WordPress plugin before 3.2.54 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Kadence Blocks | <3.2.54 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-10637 has a medium severity rating due to its potential for allowing stored cross-site scripting attacks.
To fix CVE-2024-10637, update the Gutenberg Blocks with AI by Kadence WP plugin to version 3.2.54 or later.
CVE-2024-10637 affects users with the contributor role and above who utilize the affected version of the plugin.
CVE-2024-10637 is a stored cross-site scripting (XSS) vulnerability.
CVE-2024-10637 affects versions of the Gutenberg Blocks with AI by Kadence WP plugin prior to 3.2.54.