CVE-2024-12240: Page Builder by SiteOrigin <= 2.31.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Row Label Parameter
The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the row label parameter in all versions up to, and including, 2.31.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-12240?
CVE-2024-12240 has a high severity rating due to its potential for allowing authenticated attackers to execute stored cross-site scripting.
How do I fix CVE-2024-12240?
To fix CVE-2024-12240, update the Page Builder by SiteOrigin plugin to the latest version beyond 2.31.0, which addresses the vulnerability.
Who is affected by CVE-2024-12240?
Users of the Page Builder by SiteOrigin plugin for WordPress on versions up to 2.31.0 are affected by CVE-2024-12240.
What type of attack does CVE-2024-12240 enable?
CVE-2024-12240 enables stored cross-site scripting attacks due to insufficient input sanitization and output escaping.
Can CVE-2024-12240 be exploited remotely?
Yes, CVE-2024-12240 can be exploited remotely by authenticated attackers who have access to the affected WordPress site.