CVE-2024-9645: Post Grid and Gutenberg Blocks < 2.2.93 - Contributor+ Stored XSS
The Post Grid, Posts Slider, Posts Carousel, Post Filter, Post Masonry WordPress plugin before 2.2.93 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-9645?
CVE-2024-9645 is considered a medium severity vulnerability due to its potential for unauthorized access to sensitive data.
How do I fix CVE-2024-9645?
To fix CVE-2024-9645, update the WordPress Post Grid and Gutenberg Blocks plugin to version 2.2.93 or later.
Who is affected by CVE-2024-9645?
CVE-2024-9645 affects users of the WordPress Post Grid and Gutenberg Blocks plugin below version 2.2.93.
What type of vulnerability is CVE-2024-9645?
CVE-2024-9645 is a cross-site scripting (XSS) vulnerability that can allow attackers to inject malicious scripts.
Can contributors exploit CVE-2024-9645?
Yes, users with contributor roles and above can exploit CVE-2024-9645 due to the lack of validation and escaping of block options.