Description
The Gutenverse WordPress plugin before 1.9.1 does not validate the htmlTag option in various of its block before outputting it back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Thu, 08 May 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jegstudio
Jegstudio gutenverse |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:jegstudio:gutenverse:*:*:*:*:free:wordpress:*:* | |
| Vendors & Products |
Jegstudio
Jegstudio gutenverse |
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2024-08-01T20:20:01.145Z
Reserved: 2024-04-12T08:03:33.716Z
Link: CVE-2024-3692
Updated: 2024-08-01T20:20:01.145Z
Status : Analyzed
Published: 2024-05-03T06:15:14.590
Modified: 2025-05-08T16:27:30.240
Link: CVE-2024-3692
No data.
OpenCVE Enrichment
No data.
Weaknesses