PT-2024-21797 · WordPress · Otter Blocks
Dmitry Ignatyev
·
Published
2024-04-18
·
Updated
2025-05-08
·
CVE-2024-2729
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Otter Blocks WordPress plugin versions prior to 2.6.6
Description
The issue arises from the Otter Blocks WordPress plugin not properly escaping its
mainHeadings blocks' attribute before appending it to the final rendered block. This allows contributors to conduct Stored XSS attacks.Recommendations
For versions prior to 2.6.6, update to version 2.6.6 or later to resolve the issue. As a temporary workaround, consider disabling the
mainHeadings block until a patch is available. Restrict access to the mainHeadings attribute to minimize the risk of exploitation.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Otter Blocks