CVE-2024-3692: Gutenverse < 1.9.1 - Contributor+ Stored XSS
The Gutenverse WordPress plugin before 1.9.1 does not validate the htmlTag option in various of its block before outputting it back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-3692?
CVE-2024-3692 is classified as a high-severity vulnerability due to the potential for Stored Cross-Site Scripting attacks.
How do I fix CVE-2024-3692?
To fix CVE-2024-3692, update the Gutenverse plugin to version 1.9.1 or later.
Who is affected by CVE-2024-3692?
CVE-2024-3692 affects users of the Gutenverse WordPress plugin version prior to 1.9.1.
What types of attacks can CVE-2024-3692 facilitate?
CVE-2024-3692 can facilitate Stored Cross-Site Scripting attacks, allowing malicious scripts to be executed in the context of other users.
What role must a user have to exploit CVE-2024-3692?
To exploit CVE-2024-3692, a user must have at least a contributor role in WordPress.