CVE-2024-44049: WordPress Gutenberg Blocks – Unlimited blocks For Gutenberg plugin <= 1.2.8 - Authenticated Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeHunk Gutenberg Blocks unlimited-blocks.This issue affects Gutenberg Blocks: from n/a through <= 1.2.8.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-44049?
CVE-2024-44049 is classified as a high severity vulnerability due to its ability to allow stored Cross-site Scripting (XSS).
How do I fix CVE-2024-44049?
To fix CVE-2024-44049, update the ThemeHunk Gutenberg Blocks plugin to version 1.2.8 or later where the vulnerability has been patched.
What type of vulnerability is CVE-2024-44049?
CVE-2024-44049 is a Cross-site Scripting (XSS) vulnerability that allows attackers to inject malicious scripts into web pages.
Which versions are affected by CVE-2024-44049?
CVE-2024-44049 affects versions of ThemeHunk Gutenberg Blocks from n/a up to 1.2.7.
What is the impact of CVE-2024-44049 if exploited?
If exploited, CVE-2024-44049 can lead to unauthorized access, session hijacking, or malicious redirection of users.