Reflected Cross-Site Scripting Vulnerability in Block Pattern Builder
CVE-2024-9616
6.1MEDIUM
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 11 October 2024
What is CVE-2024-9616?
The BlockMeister – Block Pattern Builder plugin for WordPress presents a security vulnerability associated with Reflected Cross-Site Scripting due to improper handling of query arguments. The vulnerability arises from the use of add_query_arg without the necessary escaping, allowing authenticated attackers to execute arbitrary scripts in the browser of unsuspecting users. Successful exploitation can occur when users engage with crafted links or actions that trigger the injection of malicious scripts, posing significant threats to both user data and site integrity.
Affected Version(s)
BlockMeister – Block Pattern Builder * <= 3.1.10