Plugin vulnerable to Stored Cross-Site Scripting via SVG File uploads
CVE-2024-9372
5.4MEDIUM
Summary
The WP Blocks Hub plugin for WordPress has a vulnerability that permits Stored Cross-Site Scripting (XSS) through SVG file uploads across all versions up to and including 1.0.2. This security flaw arises from inadequate input sanitization and output escaping, enabling authenticated users with Author-level permissions or higher to inject arbitrary web scripts. Such scripts can be executed automatically when a user accesses the compromised SVG file, potentially leading to unauthorized actions and data exposure.
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published