CVE-2024-5417: Gutentor < 3.3.6 - Contributor+ Stored XSS
Published Aug 29, 2024
·Updated
The Gutentor WordPress plugin before 3.3.6 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
Affected Software
1 affected component
Gutentor Gutentor Wordpress<3.3.6
Event History
Aug 29, 2024
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·11:15 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2024-5417?
CVE-2024-5417 has a moderate severity rating due to enabling potential Stored Cross-Site Scripting attacks.
2
How do I fix CVE-2024-5417?
To fix CVE-2024-5417, update the Gutentor plugin to version 3.3.6 or later.
3
Who is affected by CVE-2024-5417?
Users with the contributor role and above in WordPress are affected by CVE-2024-5417.
4
What types of attacks can CVE-2024-5417 allow?
CVE-2024-5417 can allow attackers to perform Stored Cross-Site Scripting attacks.
5
What versions of the Gutentor plugin are vulnerable to CVE-2024-5417?
Gutentor versions prior to 3.3.6 are vulnerable to CVE-2024-5417.