PT-2024-28924 · Kadence Wp · Gutenberg Blocks With Ai

Dmitry Ignatyev

·

Published

2024-06-03

·

Updated

2024-07-08

·

CVE-2024-4057

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions The Gutenberg Blocks with AI by Kadence WP versions prior to 3.2.37
Description The issue is related to the failure of the plugin to validate and escape some of its block attributes before outputting them back in a page or post, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. This could potentially lead to site compromise.
Recommendations For versions prior to 3.2.37, update the plugin to the latest patched version immediately. As a temporary workaround, consider restricting the contributor role and above to minimize the risk of exploitation.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-4057

Affected Products

Gutenberg Blocks With Ai