CVE-2024-2729

T

he Otter Blocks WordPress plugin before 2.6.6 does not properly escape its mainHeadings blocks' attribute before appending it to the final rendered block, allowing contributors to conduct Stored XSS attacks.

Configurations

Configuration 1 (hide)

cpe:2.3:a:themeisle:otter_blocks:*:*:*:*:*:wordpress:*:*

History

08 May 2025, 20:33

Type Values Removed Values Added
CWE CWE-79
CPE cpe:2.3:a:themeisle:otter_blocks:*:*:*:*:*:wordpress:*:*
References () https://wpscan.com/vulnerability/5014f886-020e-49d1-96a5-2159eed8ba14/ - () https://wpscan.com/vulnerability/5014f886-020e-49d1-96a5-2159eed8ba14/ - Exploit, Third Party Advisory
First Time Themeisle
Themeisle otter Blocks

21 Nov 2024, 09:10

Type Values Removed Values Added
References () https://wpscan.com/vulnerability/5014f886-020e-49d1-96a5-2159eed8ba14/ - () https://wpscan.com/vulnerability/5014f886-020e-49d1-96a5-2159eed8ba14/ -

03 Jul 2024, 01:53

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1

Information

Published : 2024-04-18 05:15

Updated : 2025-05-08 20:33


NVD link : CVE-2024-2729

Mitre link : CVE-2024-2729

CVE.ORG link : CVE-2024-2729


JSON object : View

Products Affected
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')