Reflected Cross-Site Scripting Vulnerability in Block Pattern Builder
CVE-2024-9616

6.1MEDIUM

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
11 October 2024

Summary

The BlockMeister – Block Pattern Builder plugin for WordPress presents a security vulnerability associated with Reflected Cross-Site Scripting due to improper handling of query arguments. The vulnerability arises from the use of add_query_arg without the necessary escaping, allowing authenticated attackers to execute arbitrary scripts in the browser of unsuspecting users. Successful exploitation can occur when users engage with crafted links or actions that trigger the injection of malicious scripts, posing significant threats to both user data and site integrity.

Affected Version(s)

BlockMeister – Block Pattern Builder * <= 3.1.10

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dale Mavers
.