Description

The Page Builder Gutenberg Blocks WordPress plugin before 3.1.13 does not escape the content of post embed via one of its block, which could allow users with the capability to publish posts (editor and admin by default) to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

INFO

Published Date :

2024-08-29T06:00:03.395Z

Last Modified :

2024-08-29T13:57:12.080Z

Source :

WPScan
AFFECTED PRODUCTS

The following products are affected by CVE-2024-7132 vulnerability.

Vendors Products
Godaddy
  • Coblocks
Gutentor
  • Gutenberg Blocks
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2024-7132.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact