The Gutenberg Blocks with AI by Kadence WP WordPress plugin before 3.2.39 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
History

Thu, 08 Aug 2024 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Kadencewp
Kadencewp gutenberg Blocks With Ai
CPEs cpe:2.3:a:kadencewp:gutenberg_blocks_with_ai:*:*:*:*:*:*:*:*
Vendors & Products Kadencewp
Kadencewp gutenberg Blocks With Ai
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 08 Aug 2024 06:15:00 +0000

Type Values Removed Values Added
Description The Gutenberg Blocks with AI by Kadence WP WordPress plugin before 3.2.39 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
Title Gutenberg Blocks with AI by Kadence WP < 3.2.39 - Contributor+ Stored XSS
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2024-08-08T06:00:04.409Z

Updated: 2024-08-08T18:27:36.888Z

Reserved: 2024-07-18T14:43:21.457Z

Link: CVE-2024-6884

cve-icon Vulnrichment

Updated: 2024-08-08T18:27:30.193Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-08-08T06:15:41.603

Modified: 2024-08-08T19:35:22.760

Link: CVE-2024-6884

cve-icon Redhat

No data.