CVE-2024-2729: Otter Blocks < 2.6.6 - Contributor+ Stored XSS
Published Apr 18, 2024
·Updated
The Otter Blocks WordPress plugin before 2.6.6 does not properly escape its mainHeadings blocks' attribute before appending it to the final rendered block, allowing contributors to conduct Stored XSS attacks.
Affected Software
2 affected components
Themeisle Otter Blocks Wordpress<2.6.6
Otter Blocks Otter Blocks<2.6.6
Event History
Apr 18, 2024
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
DescriptionWeakness
Data Sourced
via NVD·05:15 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2024-2729?
CVE-2024-2729 has been rated as a medium severity vulnerability due to potential Stored XSS attacks.
2
How do I fix CVE-2024-2729?
To fix CVE-2024-2729, update the Otter Blocks plugin to version 2.6.6 or later to ensure proper escaping of attributes.
3
Who is affected by CVE-2024-2729?
Anyone using Otter Blocks WordPress plugin versions prior to 2.6.6 is affected by CVE-2024-2729.
4
What type of vulnerability is CVE-2024-2729?
CVE-2024-2729 is classified as a Stored Cross-Site Scripting (XSS) vulnerability.
5
What are the risks associated with CVE-2024-2729?
The risks of CVE-2024-2729 include unauthorized access and potential data theft through the exploitation of Stored XSS attacks.