CVE · Medium

CVE-2024-12117 — Stackable – Page Builder Gutenberg Blocks [stackable-ultimate-gutenberg-blocks] < 3.13.12

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-12117 Stackable – Page Builder Gutenberg Blocks [stackable-ultimate-gutenberg-blocks] < 3.13.12 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 3.13.12 3.13.12 2025-01-21

CVE-2024-12117

The Stackable Page Builder Gutenberg Blocks plugin contains a stored cross-site scripting vulnerability affecting versions up to 3.13.11 in the Button block's title parameter, where inadequate sanitization and escaping of user input allows authenticated contributors and higher-level users to embed malicious scripts. These injected scripts execute for any visitor viewing the affected pages. The vulnerability requires at least Contributor-level permissions to exploit and is resolved in version 3.13.12.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.