CVE-2024-38682: WordPress Post Layouts for Gutenberg plugin <= 1.2.7 - Cross Site Scripting (XSS) vulnerability
Published Jul 20, 2024
·Updated
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Techeshta Post Layouts for Gutenberg allows Stored XSS.This issue affects Post Layouts for Gutenberg: from n/a through 1.2.7.
Affected Software
2 affected components
Techeshta Post Layouts for Gutenberg<=1.2.7
WordPress Post Layouts for Gutenberg<=1.2.7
Event History
Jul 20, 2024
CVE Published
via MITRE·07:44 AM
Data Sourced
via MITRE·07:44 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-38682?
CVE-2024-38682 is classified as a Stored XSS vulnerability.
2
How do I fix CVE-2024-38682?
To fix CVE-2024-38682, update Techeshta Post Layouts for Gutenberg to the latest version beyond 1.2.7.
3
What types of attacks can CVE-2024-38682 be used for?
CVE-2024-38682 can be exploited to execute arbitrary JavaScript in the context of the user’s browser.
4
Which versions of software are affected by CVE-2024-38682?
CVE-2024-38682 affects Techeshta Post Layouts for Gutenberg versions up to and including 1.2.7.
5
Is user data at risk due to CVE-2024-38682?
Yes, CVE-2024-38682 can compromise user data by allowing attackers to execute scripts that can steal session cookies or other sensitive information.