CVE-2024-4042: Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel - Combo Blocks <= 2.2.80 - Authenticated (Contributor+) Stored Cross-Site Scripting via Block Attribute
The Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' attribute of the menu-wrap-item block in all versions up to, and including, 2.2.80 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-4042?
CVE-2024-4042 is classified as a high severity vulnerability due to its potential for stored cross-site scripting.
How do I fix CVE-2024-4042?
To fix CVE-2024-4042, update the Combo Blocks plugin for WordPress to version 2.2.81 or later.
What version of the Combo Blocks plugin is affected by CVE-2024-4042?
All versions of the Combo Blocks plugin up to and including version 2.2.80 are affected by CVE-2024-4042.
What type of vulnerability is CVE-2024-4042?
CVE-2024-4042 is a stored cross-site scripting vulnerability.
Which attributes are involved in the CVE-2024-4042 vulnerability?
The 'class' attribute of the menu-wrap-item block is involved in the CVE-2024-4042 vulnerability.