Plugin vulnerable to Stored Cross-Site Scripting via SVG File uploads
CVE-2024-9372
5.4MEDIUM
Key Information:
- Vendor
Wordpress
- Status
- Vendor
- CVE Published:
- 4 October 2024
What is CVE-2024-9372?
The WP Blocks Hub plugin for WordPress has a vulnerability that permits Stored Cross-Site Scripting (XSS) through SVG file uploads across all versions up to and including 1.0.2. This security flaw arises from inadequate input sanitization and output escaping, enabling authenticated users with Author-level permissions or higher to inject arbitrary web scripts. Such scripts can be executed automatically when a user accesses the compromised SVG file, potentially leading to unauthorized actions and data exposure.