Stored Cross-site Scripting Vulnerability in Content Blocks Plugin by Johan van der Wijk
CVE-2024-44051
5.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 17 September 2024
What is CVE-2024-44051?
A vulnerability exists within the Content Blocks (Custom Post Widget) plugin developed by Johan van der Wijk that allows for improper neutralization of input during web page generation, leading to stored Cross-site Scripting (XSS) attacks. This flaw can enable an attacker to inject malicious scripts, which can be executed in the context of a user's browser leading to unauthorized actions or data theft. Users of versions prior to 3.3.5 should take immediate steps to mitigate the risk and apply necessary security patches.
Affected Version(s)
Content Blocks (Custom Post Widget) 0 <= 3.3.5