CVE-2024-4305: PostX < 4.1.0 - Contributor+ Stored XSS
The Post Grid Gutenberg Blocks and WordPress Blog Plugin WordPress plugin before 4.1.0 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-4305?
CVE-2024-4305 is rated as a moderate severity vulnerability due to its potential for unauthorized content modification.
How do I fix CVE-2024-4305?
To fix CVE-2024-4305, update the Post Grid Gutenberg Blocks and WordPress Blog Plugin to version 4.1.0 or later.
What types of users are affected by CVE-2024-4305?
Users with contributor roles and above can potentially exploit CVE-2024-4305 due to inadequate validation and escaping.
What does CVE-2024-4305 allow an attacker to do?
CVE-2024-4305 allows attackers to perform unauthorized actions by manipulating block options in the plugin.
Which versions of the plugin are impacted by CVE-2024-4305?
CVE-2024-4305 affects versions of the Post Grid Gutenberg Blocks and WordPress Blog Plugin prior to 4.1.0.