6.4
CVSSv3

CVE-2024-12268

CVSSv4: NA | CVSSv3: 6.4 | CVSSv2: NA | VMScore: 740 | EPSS: 0.00045 | KEV: Not Included
Published: 24/12/2024 Updated: 24/12/2024

Vulnerability Summary

Stored XSS Vulnerability in Responsive Blocks Plugin for WordPress

The Responsive Blocks plugin for WordPress has a Stored Cross-Site Scripting (XSS) vulnerability. This affects all versions up to 1.9.7 in the 'responsive-block-editor-addons/portfolio' block. The problem is caused by not properly cleaning input and output. Authenticated users with Contributor-level access or higher can add harmful web scripts to pages. These scripts run whenever someone visits the affected page.

Vulnerable Product Search on Vulmon Subscribe to Product

cyberchimps responsive blocks – wordpress gutenberg blocks