Cross-Site Scripting Vulnerability in Premium Blocks for WordPress by Leap13
CVE-2024-56245

6.5MEDIUM

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
2 January 2025

Summary

A Cross-Site Scripting (XSS) vulnerability has been identified in the Premium Blocks – Gutenberg Blocks for WordPress provided by Leap13. This vulnerability arises from improper neutralization of input during web page generation, leading to the potential for stored XSS attacks. This issue impacts versions from n/a up to and including 2.1.42. Attackers can exploit this weakness to inject malicious scripts, compromising the security of websites that utilize these blocks. Website administrators using the affected versions are encouraged to apply appropriate patches and maintain elevated security measures to mitigate any risks associated with this vulnerability.

Affected Version(s)

Premium Blocks – Gutenberg Blocks for WordPress <= 2.1.42

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

João Pedro S Alcântara (Kinorth) (Patchstack Alliance)
.