Stored Cross-Site Scripting in Responsive Blocks Plugin for WordPress
CVE-2024-12268

6.4MEDIUM

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
24 December 2024

Summary

The Responsive Blocks – WordPress Gutenberg Blocks plugin contains a vulnerability that allows for Stored Cross-Site Scripting (XSS) attacks. This issue arises from inadequate input sanitization and output escaping within the 'responsive-block-editor-addons/portfolio' block across all versions up to and including 1.9.7. Authenticated users with Contributor-level access or higher can inject malicious web scripts, which will execute when other users access the compromised pages. Webmasters are urged to update to version 1.9.8 or later to mitigate this risk. To secure your WordPress site, ensure you're running the latest version of all plugins and review user permissions regularly.

Affected Version(s)

Responsive Blocks – WordPress Gutenberg Blocks * <= 1.9.7

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Youcef Hamdani
.