The Otter Blocks WordPress plugin before 2.6.6 does not properly escape its mainHeadings blocks' attribute before appending it to the final rendered block, allowing contributors to conduct Stored XSS attacks.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 08 May 2025 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Themeisle
Themeisle otter Blocks |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:themeisle:otter_blocks:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Themeisle
Themeisle otter Blocks |
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2024-08-01T19:25:41.320Z
Reserved: 2024-03-20T12:41:52.548Z
Link: CVE-2024-2729
Updated: 2024-08-01T19:25:41.320Z
Status : Analyzed
Published: 2024-04-18T05:15:48.343
Modified: 2025-05-08T20:33:19.430
Link: CVE-2024-2729
No data.
OpenCVE Enrichment
No data.
Weaknesses