PT-2024-20738 · Kadence Blocks · Gutenberg Blocks

Dmitry Ignatyev

·

Published

2024-03-17

·

Updated

2024-07-03

·

CVE-2024-2509

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Gutenberg Blocks by Kadence Blocks versions prior to 3.2.26
Description The issue is related to the Gutenberg Blocks by Kadence Blocks WordPress plugin, which does not validate and escape some of its block options before outputting them back in a page/post where the block is embedded. This could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. It is estimated that over 400,000 active installations are potentially affected.
Recommendations For versions prior to 3.2.26, update to version 3.2.26 or later to resolve the issue. As a temporary workaround, consider restricting the use of the vulnerable block options to minimize the risk of exploitation.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-2509

Affected Products

Gutenberg Blocks