CVE-2024-9218: Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid <= 1.3.14 - Reflected Cross-Site Scripting
The Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of addqueryarg without appropriate escaping on the URL in all versions up to, and including, 1.3.14. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2024-9218?
CVE-2024-9218 is classified as a high severity vulnerability due to its impact on the security of WordPress sites.
How do I fix CVE-2024-9218?
To fix CVE-2024-9218, update the Magazine Blocks plugin for WordPress to version 1.3.15 or later.
What type of vulnerability is CVE-2024-9218?
CVE-2024-9218 is a reflected cross-site scripting (XSS) vulnerability.
Which versions of the Magazine Blocks plugin are affected by CVE-2024-9218?
CVE-2024-9218 affects all versions of the Magazine Blocks plugin up to and including version 1.3.14.
Who is the vendor for CVE-2024-9218?
The vendor for CVE-2024-9218 is Themegrill, the developer of the Magazine Blocks plugin.