CVE-2024-7132: CoBlocks < 3.1.13 - Editor+ Stored XSS
The Page Builder Gutenberg Blocks WordPress plugin before 3.1.13 does not escape the content of post embed via one of its block, which could allow users with the capability to publish posts (editor and admin by default) to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup)
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-7132?
CVE-2024-7132 is considered a high severity vulnerability due to its potential for Stored Cross-Site Scripting attacks.
How do I fix CVE-2024-7132?
To fix CVE-2024-7132, you should update the Page Builder Gutenberg Blocks WordPress plugin to version 3.1.13 or later.
Who is affected by CVE-2024-7132?
Users with the capability to publish posts, typically editors and admins, are affected by CVE-2024-7132.
What types of attacks could result from CVE-2024-7132?
CVE-2024-7132 could allow attackers to perform Stored Cross-Site Scripting attacks.
Which versions of the WordPress plugin are vulnerable to CVE-2024-7132?
Versions of the Page Builder Gutenberg Blocks WordPress plugin prior to 3.1.13 are vulnerable to CVE-2024-7132.