PT-2024-38098 · WordPress · Page Builder Gutenberg Blocks

Dmitry Ignatyev

·

Published

2024-08-28

·

Updated

2024-10-07

·

CVE-2024-7132

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Page Builder Gutenberg Blocks WordPress plugin versions prior to 3.1.13
Description The issue concerns the Page Builder Gutenberg Blocks WordPress plugin, which does not properly escape the content of post embeds via one of its blocks. This could allow users with the capability to publish posts, such as editors and administrators by default, to perform Stored Cross-Site Scripting attacks. This vulnerability can be exploited even when the unfiltered html capability is disallowed, for example, in a multisite setup.
Recommendations For versions prior to 3.1.13, update to version 3.1.13 or later to resolve the issue. As a temporary workaround, consider restricting the capability to publish posts to trusted users only, until the update is applied. Additionally, restrict access to the post embed block to minimize the risk of exploitation.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-7132

Affected Products

Page Builder Gutenberg Blocks