← back
CVE-2024-2761

Genesis Blocks < 3.1.3 - Contributor+ Stored XSS

CVSS 6.8 MEDIUMEPSS 0.7%
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 6.8EPSS 0.7%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
19 Apr 2024Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
The Genesis Blocks WordPress plugin before 3.1.3 does not properly escape data input provided to some of its blocks, allowing using with at least contributor privileges to conduct Stored XSS attacks.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N
Affected products
Unknown · Genesis Blocks