CVE-2024-38712: WordPress Qi Blocks plugin <= 1.3 - Cross Site Scripting (XSS) vulnerability
Published Jul 20, 2024
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Qode Qi Blocks qi-blocks.This issue affects Qi Blocks: from n/a through <= 1.3.
Affected Software
3 affected components
Qode Interactive Qi Blocks<=1.3
WordPress Qi Blocks<=1.3
Qodeinteractive Qi Blocks Wordpress<1.3.1
Remediation
Information
Update to 1.3.1 or a higher version.
Event History
Jul 20, 2024
CVE Published
via MITRE·07:26 AM
Data Sourced
via MITRE·07:26 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 AM
DescriptionSeverityWeaknessAffected Software
Jul 16, 58279
Event
via MITRE·06:47 AM
Frequently Asked Questions
1
What is the severity of CVE-2024-38712?
CVE-2024-38712 is classified as a high-severity vulnerability due to its potential for stored cross-site scripting (XSS) attacks.
2
How do I fix CVE-2024-38712?
To fix CVE-2024-38712, update the Qode Interactive Qi Blocks plugin to version 1.4 or higher.
3
What type of vulnerability is CVE-2024-38712?
CVE-2024-38712 is an Improper Neutralization of Input During Web Page Generation vulnerability, also known as XSS.
4
Which versions of Qi Blocks are affected by CVE-2024-38712?
CVE-2024-38712 affects all versions of Qi Blocks up to and including version 1.3.
5
What software is impacted by CVE-2024-38712?
CVE-2024-38712 impacts both Qode Interactive Qi Blocks and WordPress Qi Blocks.