CVE-2024-2729

The Otter Blocks WordPress plugin before 2.6.6 does not properly escape its mainHeadings blocks' attribute before appending it to the final rendered block, allowing contributors to conduct Stored XSS attacks.
Configurations

Configuration 1 (hide)

cpe:2.3:a:themeisle:otter_blocks:*:*:*:*:*:wordpress:*:*

History

08 May 2025, 20:33

Type Values Removed Values Added
CPE cpe:2.3:a:themeisle:otter_blocks:*:*:*:*:*:wordpress:*:*
First Time Themeisle otter Blocks
Themeisle
References () https://wpscan.com/vulnerability/5014f886-020e-49d1-96a5-2159eed8ba14/ - () https://wpscan.com/vulnerability/5014f886-020e-49d1-96a5-2159eed8ba14/ - Exploit, Third Party Advisory
CWE CWE-79

21 Nov 2024, 09:10

Type Values Removed Values Added
References () https://wpscan.com/vulnerability/5014f886-020e-49d1-96a5-2159eed8ba14/ - () https://wpscan.com/vulnerability/5014f886-020e-49d1-96a5-2159eed8ba14/ -

03 Jul 2024, 01:53

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1

18 Apr 2024, 13:04

Type Values Removed Values Added
Summary
  • (es) El complemento Otter Blocks de WordPress anterior a 2.6.6 no escapa correctamente del atributo de sus bloques mainHeadings antes de agregarlo al bloque renderizado final, lo que permite a los contribuyentes realizar ataques XSS almacenados.

18 Apr 2024, 05:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-04-18 05:15

Updated : 2025-05-08 20:33


NVD link : CVE-2024-2729

Mitre link : CVE-2024-2729

CVE.ORG link : CVE-2024-2729


JSON object : View

Products Affected

themeisle

  • otter_blocks
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')