Unrated severityNVD Advisory· Published Jun 17, 2024· Updated Aug 1, 2024
PostX < 4.1.0 - Contributor+ Stored XSS
CVE-2024-4305
Description
The Post Grid Gutenberg Blocks and WordPress Blog Plugin WordPress plugin before 4.1.0 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- WordPress/Post Grid Gutenberg Blocks and WordPress Blog Plugindescription
- Range: <4.1.0
Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/635be98d-4c17-4e75-871f-9794d85a2eb1/mitreexploitvdb-entrytechnical-description
News mentions
0No linked articles in our index yet.