CVE Database /
CVE-2024-10367
CVE · Medium
CVE-2024-10367 — Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE [otter-blocks] < 3.0.5
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-10367
|
Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE [otter-blocks] < 3.0.5 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
6.4
|
< 3.0.5
|
3.0.5 |
2024-10-31 |
—
|
CVE-2024-10367
The Otter Blocks plugin through version 3.0.4 contains a stored cross-site scripting vulnerability in its REST API SVG file upload functionality, stemming from inadequate sanitization of input and escaping of output. Attackers with Author-level permissions or higher can inject malicious scripts into SVG files, which execute when users access those files. The vulnerability affects all versions up to and including 3.0.4 and is fixed in version 3.0.5.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings