The Essential Blocks WordPress plugin before 4.7.0 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: WPScan
Published: 2024-08-02T06:00:06.949Z
Updated: 2024-08-02T16:12:09.234Z
Reserved: 2024-06-03T08:54:49.037Z
Link: CVE-2024-5595
Vulnrichment
Updated: 2024-08-02T16:11:51.471Z
NVD
Status : Awaiting Analysis
Published: 2024-08-02T06:15:54.263
Modified: 2024-08-02T17:35:43.927
Link: CVE-2024-5595
Redhat
No data.