PostX Gutenberg Blocks Saved Templates Addon < 2.4.10 - Contributor+ Stored Cross-Site Scripting
CVE-2021-24660
5.4MEDIUM
What is CVE-2021-24660?
The PostX – Gutenberg Blocks for Post Grid WordPress plugin before 2.4.10, with Saved Templates Addon enabled, allows users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks via the plugin's shortcode.
Affected Version(s)
PostX – Gutenberg Blocks for Post Grid 2.4.10