First published: Sun Jul 21 2024(Updated: )
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Gutenberg Team Gutenberg allows Stored XSS.This issue affects Gutenberg: from n/a through 18.6.0.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Gutenberg | <=18.6.0 | |
WordPress Gutenberg | <=18.6.0 |
Update to 18.6.1 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-37492 has been classified as a high severity vulnerability due to its potential for enabling stored cross-site scripting (XSS).
To fix CVE-2024-37492, update the Gutenberg plugin to version 18.6.1 or later, as this version addresses the vulnerability.
CVE-2024-37492 affects users of Gutenberg version 18.6.0 and earlier, including the Gutenberg plugin for WordPress.
The potential impacts of CVE-2024-37492 include unauthorized data access and the execution of malicious scripts on users' browsers.
CVE-2024-37492 can be easily exploited by attackers to inject malicious scripts, especially in environments that allow user-generated content.