CSS Injection Vulnerability in Page Builder Gutenberg Blocks Plugin
CVE-2024-8760
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 12 October 2024
What is CVE-2024-8760?
The Stackable β Page Builder Gutenberg Blocks plugin for WordPress is vulnerable to CSS Injection in all versions up to, and including, 3.13.6. This makes it possible for unauthenticated attackers to embed untrusted style information into comments resulting in a possibility of data exfiltration such as admin nonces with limited impact. These nonces could be used to perform CSRF attacks within a limited time window. The presence of other plugins may make additional nonces available, which may pose a risk in plugins that don't perform capability checks to protect AJAX actions or other actions reachable by lower-privileged users.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Stackable β Page Builder Gutenberg Blocks * <= 3.13.6
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved