Stored XSS Vulnerability in FancyPost - Best Ultimate Post Block, Post Grid, Layouts, Carousel, Slider For Gutenberg & Elementor
CVE-2024-38686
6.5MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 20 July 2024
What is CVE-2024-38686?
A cross-site scripting (XSS) vulnerability exists in the Pluginic FancyPost, a plugin designed for WordPress that allows users to display posts in various formats. This vulnerability stems from improper sanitization of user input during web page generation, enabling attackers to inject malicious scripts that can be executed in the context of the user's browser. As a result, this flaw poses a risk of stored XSS attacks, potentially compromising user data and session information when the affected plugin versions are enabled.
Affected Version(s)
FancyPost – Best Ultimate Post Block, Post Grid, Layouts, Carousel, Slider For Gutenberg & Elementor <= 5.3.1