PostX Gutenberg Blocks Saved Templates Addon < 2.4.10 - Contributor+ Stored Cross-Site Scripting
CVE-2021-24660
5.4MEDIUM
What is CVE-2021-24660?
The PostX β Gutenberg Blocks for Post Grid WordPress plugin before 2.4.10, with Saved Templates Addon enabled, allows users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks via the plugin's shortcode.
Affected Version(s)
PostX β Gutenberg Blocks for Post Grid 2.4.10