CVE-2024-3344: Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE <= 2.6.8 - Authenticated (Author+) Limited File Upload to Stored Cross-Site Scripting
The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG file upload in all versions up to, and including, 2.6.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-3344?
CVE-2024-3344 has a medium severity rating due to the potential for stored cross-site scripting attacks.
How do I fix CVE-2024-3344?
To fix CVE-2024-3344, update the Otter Blocks plugin to version 2.6.9 or later.
What versions of Otter Blocks are affected by CVE-2024-3344?
All versions of Otter Blocks up to and including 2.6.8 are affected by CVE-2024-3344.
What type of vulnerability is CVE-2024-3344?
CVE-2024-3344 is a stored cross-site scripting vulnerability that arises from insufficient input sanitization.
Can CVE-2024-3344 be exploited without authentication?
No, CVE-2024-3344 requires an authenticated user to exploit the stored cross-site scripting vulnerability.