Reflected Cross-Site Scripting Vulnerability in Block Pattern Builder
CVE-2024-9616
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 11 October 2024
What is CVE-2024-9616?
The BlockMeister β Block Pattern Builder plugin for WordPress presents a security vulnerability associated with Reflected Cross-Site Scripting due to improper handling of query arguments. The vulnerability arises from the use of add_query_arg without the necessary escaping, allowing authenticated attackers to execute arbitrary scripts in the browser of unsuspecting users. Successful exploitation can occur when users engage with crafted links or actions that trigger the injection of malicious scripts, posing significant threats to both user data and site integrity.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
BlockMeister β Block Pattern Builder * <= 3.1.10
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved