Stored XSS Vulnerability in FancyPost - Best Ultimate Post Block, Post Grid, Layouts, Carousel, Slider For Gutenberg & Elementor
CVE-2024-38686

6.5MEDIUM

Key Information:

Vendor
Pluginic
Status
Fancypost – Best Ultimate Post Block, Post Grid, Layouts, Carousel, Slider For Gutenberg & Elementor
Vendor
CVE Published:
20 July 2024

Summary

A cross-site scripting (XSS) vulnerability exists in the Pluginic FancyPost, a plugin designed for WordPress that allows users to display posts in various formats. This vulnerability stems from improper sanitization of user input during web page generation, enabling attackers to inject malicious scripts that can be executed in the context of the user's browser. As a result, this flaw poses a risk of stored XSS attacks, potentially compromising user data and session information when the affected plugin versions are enabled.

Affected Version(s)

FancyPost – Best Ultimate Post Block, Post Grid, Layouts, Carousel, Slider For Gutenberg & Elementor <= 5.3.1

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

4rCanJ0x! (Patchstack Alliance)
.