CVE Database /
CVE-2024-6884
CVE · Medium
CVE-2024-6884 — Kadence Blocks — Page Builder Toolkit for Gutenberg Editor [kadence-blocks] < 3.2.39
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-6884
|
Kadence Blocks — Page Builder Toolkit for Gutenberg Editor [kadence-blocks] < 3.2.39 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
5.4
|
< 3.2.53
|
3.2.53 |
2024-07-18 |
—
|
CVE-2024-6884
A vulnerability exists in the Gutenberg Blocks with AI by Kadence WP plugin for WordPress, affecting versions up to 3.2.38. The issue arises from inadequate validation and encoding of user input in the Countdown Block's Days Label field, allowing authenticated attackers with Contributor-level access or higher to inject malicious scripts that will be executed when the affected page is accessed. This enables attackers to potentially inject arbitrary web scripts, compromising the security of the WordPress site.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings