Stored Cross-Site Scripting in Responsive Blocks Plugin for WordPress
CVE-2024-12268
Key Information:
- Vendor
- Wordpress
- Vendor
- CVE Published:
- 24 December 2024
Summary
The Responsive Blocks – WordPress Gutenberg Blocks plugin contains a vulnerability that allows for Stored Cross-Site Scripting (XSS) attacks. This issue arises from inadequate input sanitization and output escaping within the 'responsive-block-editor-addons/portfolio' block across all versions up to and including 1.9.7. Authenticated users with Contributor-level access or higher can inject malicious web scripts, which will execute when other users access the compromised pages. Webmasters are urged to update to version 1.9.8 or later to mitigate this risk. To secure your WordPress site, ensure you're running the latest version of all plugins and review user permissions regularly.
Affected Version(s)
Responsive Blocks – WordPress Gutenberg Blocks * <= 1.9.7
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved