CVE-2024-2369: Page Builder Gutenberg Blocks < 3.1.7 - Contributor+ Stored XSS
The Page Builder Gutenberg Blocks WordPress plugin before 3.1.7 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-2369?
CVE-2024-2369 is considered a medium severity vulnerability due to the potential for Stored Cross-Site Scripting (XSS) attacks.
How do I fix CVE-2024-2369?
To fix CVE-2024-2369, update the Page Builder Gutenberg Blocks WordPress plugin to version 3.1.7 or later.
Who is affected by CVE-2024-2369?
Users with the contributor role and above in WordPress are affected by CVE-2024-2369.
What type of vulnerability is CVE-2024-2369?
CVE-2024-2369 is a Stored Cross-Site Scripting (XSS) vulnerability.
What software versions are impacted by CVE-2024-2369?
CVE-2024-2369 affects versions of the Page Builder Gutenberg Blocks plugin prior to 3.1.7.