CVE-2024-2509: Gutenberg Blocks by Kadence Blocks < 3.2.26 - Contributor+ Stored XSS
The Gutenberg Blocks by Kadence Blocks WordPress plugin before 3.2.26 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-2509?
The severity of CVE-2024-2509 is considered to be high due to its potential for Stored Cross-Site Scripting vulnerabilities.
How do I fix CVE-2024-2509?
To fix CVE-2024-2509, update the Gutenberg Blocks by Kadence Blocks plugin to version 3.2.26 or later.
Who is affected by CVE-2024-2509?
Users with the contributor role and above in WordPress are potentially affected by CVE-2024-2509.
What is the cause of CVE-2024-2509?
CVE-2024-2509 is caused by the lack of validation and escaping of block options in the Gutenberg Blocks by Kadence Blocks WordPress plugin.
What type of attack is possible with CVE-2024-2509?
CVE-2024-2509 allows for Stored Cross-Site Scripting (XSS) attacks which can compromise the security of the WordPress site.