Cross-Site Scripting Vulnerability in Premium Blocks for WordPress by Leap13
CVE-2024-56245
Key Information:
- Vendor
- Wordpress
- Vendor
- CVE Published:
- 2 January 2025
Summary
A Cross-Site Scripting (XSS) vulnerability has been identified in the Premium Blocks – Gutenberg Blocks for WordPress provided by Leap13. This vulnerability arises from improper neutralization of input during web page generation, leading to the potential for stored XSS attacks. This issue impacts versions from n/a up to and including 2.1.42. Attackers can exploit this weakness to inject malicious scripts, compromising the security of websites that utilize these blocks. Website administrators using the affected versions are encouraged to apply appropriate patches and maintain elevated security measures to mitigate any risks associated with this vulnerability.
Affected Version(s)
Premium Blocks – Gutenberg Blocks for WordPress <= 2.1.42
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved