CVE-2024-4158: Blocksy <= 2.0.42 - Authenticated (Contributor+) Stored Cross-Site Scripting
The Blocksy theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘tagName’ parameter in versions up to, and including, 2.0.42 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-4158?
CVE-2024-4158 is considered a critical vulnerability due to its potential for stored cross-site scripting attacks.
How do I fix CVE-2024-4158?
To fix CVE-2024-4158, update the Blocksy theme to version 2.0.43 or later.
Who is affected by CVE-2024-4158?
CVE-2024-4158 affects users of the Blocksy theme for WordPress versions 2.0.42 and below.
What type of attack is possible with CVE-2024-4158?
CVE-2024-4158 allows authenticated attackers to perform stored cross-site scripting attacks via the ‘tagName’ parameter.
Is input sanitization a concern in CVE-2024-4158?
Yes, CVE-2024-4158 is due to insufficient input sanitization and output escaping in the Blocksy theme.