CVE Database /
CVE-2024-8760
CVE · Medium
CVE-2024-8760 — Stackable – Page Builder Gutenberg Blocks [stackable-ultimate-gutenberg-blocks] < 3.13.7
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-8760
|
Stackable – Page Builder Gutenberg Blocks [stackable-ultimate-gutenberg-blocks] < 3.13.7 |
Improper Control of Generation of Code ('Code Injection') |
Medium
5.3
|
< 3.13.7
|
3.13.7 |
2024-10-11 |
—
|
CVE-2024-8760
The Stackable – Page Builder Gutenberg Blocks plugin for WordPress contains a vulnerability in all versions up to 3.13.6 that allows unauthenticated attackers to inject malicious CSS code into comments, potentially leading to data theft and CSRF attacks within a short timeframe. This issue could be exploited to obtain sensitive information such as admin nonces, which might be used to compromise other plugins lacking adequate capability checks for AJAX actions or lower-privileged user access.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings