Plugin Vulnerable to Stored Cross-Site Scripting
CVE-2024-12581
Key Information:
- Vendor
- Wordpress
- Vendor
- CVE Published:
- 13 December 2024
Summary
The Gutenberg Blocks with AI by Kadence WP - Page Builder Features plugin for WordPress is susceptible to Stored Cross-Site Scripting (XSS) vulnerabilities due to inadequate input sanitization and output escaping measures. This flaw permits authenticated attackers, specifically those with administrator-level permissions or higher, to inject arbitrary scripts within pages. Such scripts execute whenever a user accesses the compromised page, posing significant risks, especially in multi-site WordPress installations where the unfiltered_html setting is disabled. Users are urged to take immediate action to validate their installations and apply necessary updates.
Affected Version(s)
Gutenberg Blocks with AI by Kadence WP – Page Builder Features * <= 3.2.53
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved