CVE-2024-6884: Gutenberg Blocks with AI by Kadence WP < 3.2.39 - Contributor+ Stored XSS
The Gutenberg Blocks with AI by Kadence WP WordPress plugin before 3.2.39 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-6884?
CVE-2024-6884 has a severity rating that indicates a significant risk for users, specifically related to Stored Cross-Site Scripting (XSS).
How do I fix CVE-2024-6884?
To fix CVE-2024-6884, update the Kadence WP Gutenberg Blocks with AI plugin to version 3.2.39 or later.
Who is affected by CVE-2024-6884?
CVE-2024-6884 affects users of the Kadence WP Gutenberg Blocks with AI plugin prior to version 3.2.39, particularly those with contributor roles and above.
What type of vulnerability is CVE-2024-6884?
CVE-2024-6884 is classified as a Stored Cross-Site Scripting (XSS) vulnerability.
What actions should users with affected versions of Kadence WP Gutenberg Blocks with AI take regarding CVE-2024-6884?
Users with affected versions should immediately update their plugin to version 3.2.39 or higher to mitigate the risk associated with CVE-2024-6884.