CVE-2024-2761
Genesis Blocks < 3.1.3 - Contributor+ Stored XSS
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 6.8EPSS 0.7%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
19 Apr 2024Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
The Genesis Blocks WordPress plugin before 3.1.3 does not properly escape data input provided to some of its blocks, allowing using with at least contributor privileges to conduct Stored XSS attacks.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N
Affected products
Unknown · Genesis Blocks