First published: Tue May 14 2024(Updated: )
The Ultimate Blocks WordPress plugin before 3.1.7 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ultimate Blocks | <3.1.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2024-3241 is considered medium due to the potential for Stored Cross-Site Scripting attacks.
To fix CVE-2024-3241, update the Ultimate Blocks WordPress plugin to version 3.1.7 or later.
Users with the contributor role and above on WordPress sites using Ultimate Blocks before version 3.1.7 are affected by CVE-2024-3241.
CVE-2024-3241 can enable Stored Cross-Site Scripting (XSS) attacks on affected WordPress sites.
There are no known effective workarounds for CVE-2024-3241; immediate updating is recommended.