PT-2024-27579 · WordPress · Blocksy

Ancorn

+1

·

Published

2024-05-02

·

Updated

2024-05-02

·

CVE-2024-3747

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Blocksy theme for WordPress versions up to, and including, 2.0.39
Description The issue is related to Stored Cross-Site Scripting via the className parameter in the About Me block due to insufficient input sanitization and output escaping. This allows authenticated attackers with contributor access and above to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Recommendations For Blocksy theme for WordPress versions up to, and including, 2.0.39, consider updating to a version that addresses the insufficient input sanitization and output escaping issue. As a temporary workaround, restrict access to the About Me block or limit the ability to inject scripts through the className parameter until a patch is available.

Fix

XSS

RCE

Weakness Enumeration

Related Identifiers

CVE-2024-3747

Affected Products

Blocksy