Stored Cross-site Scripting Vulnerability in Content Blocks Plugin by Johan van der Wijk
CVE-2024-44051

5.4MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
17 September 2024

What is CVE-2024-44051?

A vulnerability exists within the Content Blocks (Custom Post Widget) plugin developed by Johan van der Wijk that allows for improper neutralization of input during web page generation, leading to stored Cross-site Scripting (XSS) attacks. This flaw can enable an attacker to inject malicious scripts, which can be executed in the context of a user's browser leading to unauthorized actions or data theft. Users of versions prior to 3.3.5 should take immediate steps to mitigate the risk and apply necessary security patches.

Affected Version(s)

Content Blocks (Custom Post Widget) 0 <= 3.3.5

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

.