CVE · Medium

CVE-2024-8760 — Stackable – Page Builder Gutenberg Blocks [stackable-ultimate-gutenberg-blocks] < 3.13.7

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-8760 Stackable – Page Builder Gutenberg Blocks [stackable-ultimate-gutenberg-blocks] < 3.13.7 Improper Control of Generation of Code ('Code Injection') Medium 5.3 < 3.13.7 3.13.7 2024-10-11

CVE-2024-8760

The Stackable – Page Builder Gutenberg Blocks plugin for WordPress contains a vulnerability in all versions up to 3.13.6 that allows unauthenticated attackers to inject malicious CSS code into comments, potentially leading to data theft and CSRF attacks within a short timeframe. This issue could be exploited to obtain sensitive information such as admin nonces, which might be used to compromise other plugins lacking adequate capability checks for AJAX actions or lower-privileged user access.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.