CVE-2024-3239: PostX < 4.0.2 - Contributor+ Stored XSS
The Post Grid Gutenberg Blocks and WordPress Blog Plugin WordPress plugin before 4.0.2 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-3239?
CVE-2024-3239 has a medium severity rating due to its potential impact on website security through improper input validation.
How can I fix CVE-2024-3239?
To fix CVE-2024-3239, update the Post Grid Gutenberg Blocks and WordPress Blog Plugin to version 4.0.2 or higher.
Who is affected by CVE-2024-3239?
Users with the contributor role and above are affected by CVE-2024-3239 as they can leverage the vulnerability to execute unauthorized actions.
What versions are vulnerable to CVE-2024-3239?
Versions of the Post Grid Gutenberg Blocks and WordPress Blog Plugin prior to 4.0.2 are vulnerable to CVE-2024-3239.
What types of attacks can CVE-2024-3239 enable?
CVE-2024-3239 could enable users to perform stored cross-site scripting (XSS) attacks by manipulating block options.