CVE-2024-7132 exposes a critical flaw in the CoBlocks plugin, a widely used WordPress extension with over 400,000 installations. This Stored XSS vulnerability can be exploited by contributors to embed malicious JavaScript code within posts, leading to unauthorized actions, including the creation of admin accounts. The vulnerability highlights the significant security risks associated with improper input validation in WordPress plugins, particularly in environments where user roles and permissions are not tightly controlled.
CVE-2024-7132 – CoBlocks – Stored XSS to Admin Account Creation – POC
![CVE-2024-7132 – CoBlocks – Stored XSS to Admin Account Creation – POC CVE-2024-7132 – CoBlocks – Stored XSS to Admin Account Creation – POC](https://research.cleantalk.org/wp-content/uploads/2023/10/New_1_not_safe-1.png)