Stored Cross-Site Scripting Vulnerability Affects Blocksy Theme
CVE-2024-11420
What is CVE-2024-11420?
The Blocksy WordPress theme experiences a vulnerability that allows for Stored Cross-Site Scripting via the Contact Info Block link parameter, affecting all versions up to and including 2.0.77. This issue arises from insufficient input sanitization and output escaping, enabling authenticated attackers with Contributor-level access or higher to inject arbitrary web scripts. The scripts execute whenever a user accesses a page that has been manipulated, potentially leading to severe security risks for both site administrators and visitors.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Blocksy * <= 2.0.77
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved