The Page Builder Gutenberg Blocks WordPress plugin before 3.1.13 does not escape the content of post embed via one of its block, which could allow users with the capability to publish posts (editor and admin by default) to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
History

Mon, 07 Oct 2024 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Godaddy
Godaddy coblocks
Weaknesses CWE-79
CPEs cpe:2.3:a:godaddy:coblocks:*:*:*:*:*:wordpress:*:*
Vendors & Products Godaddy
Godaddy coblocks

Thu, 29 Aug 2024 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Gutentor
Gutentor gutenberg Blocks
CPEs cpe:2.3:a:gutentor:gutenberg_blocks:*:*:*:*:*:*:*:*
Vendors & Products Gutentor
Gutentor gutenberg Blocks
Metrics cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 29 Aug 2024 06:15:00 +0000

Type Values Removed Values Added
Description The Page Builder Gutenberg Blocks WordPress plugin before 3.1.13 does not escape the content of post embed via one of its block, which could allow users with the capability to publish posts (editor and admin by default) to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
Title CoBlocks < 3.1.13 - Editor+ Stored XSS
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2024-08-29T06:00:03.395Z

Updated: 2024-08-29T13:57:12.080Z

Reserved: 2024-07-26T15:36:13.583Z

Link: CVE-2024-7132

cve-icon Vulnrichment

Updated: 2024-08-29T13:57:04.542Z

cve-icon NVD

Status : Analyzed

Published: 2024-08-29T11:15:28.463

Modified: 2024-10-07T15:44:37.107

Link: CVE-2024-7132

cve-icon Redhat

No data.