CVE-2024-24871: WordPress Blocksy theme <= 2.0.19 - Cross Site Scripting (XSS) vulnerability
Published Feb 8, 2024
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in creativethemeshq Blocksy blocksy.This issue affects Blocksy: from n/a through <= 2.0.19.
Affected Software
1 affected component
creativethemes Blocksy Wordpress<=2.0.19
Remediation
Information
Update to 2.0.20 or a higher version.
Event History
Feb 8, 2024
CVE Published
via MITRE·01:06 PM
Data Sourced
via MITRE·01:06 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-24871?
CVE-2024-24871 is a medium severity vulnerability categorized as a Stored Cross-Site Scripting (XSS) issue.
2
How do I fix CVE-2024-24871?
To fix CVE-2024-24871, update the Blocksy theme to version 2.0.20 or later.
3
What versions of Blocksy are affected by CVE-2024-24871?
CVE-2024-24871 affects all versions of Blocksy from n/a up to and including 2.0.19.
4
What does CVE-2024-24871 allow an attacker to do?
CVE-2024-24871 allows an attacker to execute arbitrary JavaScript code in the context of a victim's browser session.
5
Is CVE-2024-24871 a common vulnerability in WordPress themes?
Yes, CVE-2024-24871 is an instance of a common Cross-Site Scripting vulnerability found in WordPress themes.