CVE · Medium

CVE-2024-6884 — Kadence Blocks — Page Builder Toolkit for Gutenberg Editor [kadence-blocks] < 3.2.39

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-6884 Kadence Blocks — Page Builder Toolkit for Gutenberg Editor [kadence-blocks] < 3.2.39 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 3.2.53 3.2.53 2024-07-18

CVE-2024-6884

A vulnerability exists in the Gutenberg Blocks with AI by Kadence WP plugin for WordPress, affecting versions up to 3.2.38. The issue arises from inadequate validation and encoding of user input in the Countdown Block's Days Label field, allowing authenticated attackers with Contributor-level access or higher to inject malicious scripts that will be executed when the affected page is accessed. This enables attackers to potentially inject arbitrary web scripts, compromising the security of the WordPress site.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.