CVE-2024-2729

The Otter Blocks WordPress plugin before 2.6.6 does not properly escape its mainHeadings blocks' attribute before appending it to the final rendered block, allowing contributors to conduct Stored XSS attacks.
Configurations

Configuration 1 (hide)

cpe:2.3:a:themeisle:otter_blocks:*:*:*:*:*:wordpress:*:*

History

08 May 2025, 20:33

Type Values Removed Values Added
CPE cpe:2.3:a:themeisle:otter_blocks:*:*:*:*:*:wordpress:*:*
First Time Themeisle
Themeisle otter Blocks
References () https://wpscan.com/vulnerability/5014f886-020e-49d1-96a5-2159eed8ba14/ - () https://wpscan.com/vulnerability/5014f886-020e-49d1-96a5-2159eed8ba14/ - Exploit, Third Party Advisory
CWE CWE-79

Information

Published : 2024-04-18 05:15

Updated : 2025-05-08 20:33


NVD link : CVE-2024-2729

Mitre link : CVE-2024-2729

CVE.ORG link : CVE-2024-2729


JSON object : View

Products Affected

themeisle

  • otter_blocks
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')