First published: Sun Apr 07 2024(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPDeveloper Essential Blocks for Gutenberg allows Stored XSS.This issue affects Essential Blocks for Gutenberg: from n/a through 4.5.3.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Essential Blocks | <4.5.4 | |
Essential Blocks for Gutenberg | <4.5.3 | |
Essential Blocks | <4.5.3 |
Update to 4.5.4 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-31306 has been classified as a critical vulnerability due to its potential for stored cross-site scripting (XSS).
To fix CVE-2024-31306, update the Essential Blocks for Gutenberg plugin to version 4.5.4 or later.
CVE-2024-31306 affects Essential Blocks for Gutenberg versions from n/a through 4.5.3.
CVE-2024-31306 is an improper neutralization of input vulnerability that leads to stored cross-site scripting (XSS).
The vendor for CVE-2024-31306 is WPDeveloper, the creator of the Essential Blocks for Gutenberg plugin.