CVE · Medium

CVE-2024-10367 — Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE [otter-blocks] < 3.0.5

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-10367 Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE [otter-blocks] < 3.0.5 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 3.0.5 3.0.5 2024-10-31

CVE-2024-10367

The Otter Blocks plugin through version 3.0.4 contains a stored cross-site scripting vulnerability in its REST API SVG file upload functionality, stemming from inadequate sanitization of input and escaping of output. Attackers with Author-level permissions or higher can inject malicious scripts into SVG files, which execute when users access those files. The vulnerability affects all versions up to and including 3.0.4 and is fixed in version 3.0.5.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.