CVE-2024-32961: WordPress Blocksy theme <= 2.0.33 - Cross Site Scripting (XSS) vulnerability
Published Apr 25, 2024
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in creativethemeshq Blocksy blocksy.This issue affects Blocksy: from n/a through <= 2.0.33.
Affected Software
3 affected components
Creative Themes Blocksy<=2.0.33
WordPress Blocksy<=2.0.33
creativethemes Blocksy Wordpress<2.0.34
Remediation
Information
Update to 2.0.34 or a higher version.
Event History
Apr 25, 2024
CVE Published
via MITRE·09:16 AM
Data Sourced
via MITRE·09:16 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-32961?
CVE-2024-32961 is characterized as a Stored Cross-site Scripting (XSS) vulnerability.
2
How do I fix CVE-2024-32961?
To fix CVE-2024-32961, update the Blocksy theme to version 2.0.34 or later.
3
Which versions of Blocksy are affected by CVE-2024-32961?
CVE-2024-32961 affects all versions of Blocksy from n/a through 2.0.33.
4
Can CVE-2024-32961 expose my website to attacks?
Yes, CVE-2024-32961 could potentially allow attackers to inject malicious scripts into your website.
5
Is there a workaround for CVE-2024-32961 if I cannot update immediately?
A temporary workaround for CVE-2024-32961 may include disabling features that allow user-generated content.