cleantalk
Vulnerabilities and Security Researches

Page Builder Gutenberg Blocks – CoBlocks, CVE-2024-7132

CVE, Research URL

CVE-2024-7132

Published on
Aug 29, 2024
Research Description
The Page Builder Gutenberg Blocks WordPress plugin before 3.1.13 does not escape the content of post embed via one of its block, which could allow users with the capability to publish posts (editor and admin by default) to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
Affected versions
max 3.1.13.
Status
vulnerable