CVE-2024-10867
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Published Jan 31, 2025
CWE ID 79
Summary
CVE-2024-10867 is a stored Cross-Site Scripting (XSS) vulnerability affecting the Borderless plugin for WordPress, used in Elementor & Gutenberg. Versions up to 1.5.9 are vulnerable. This issue stems from insufficient sanitization and output escaping of SVG file uploads. Attackers with Author-level access and above can exploit this, injecting malicious scripts that execute whenever a user accesses the infected SVG file. Consequently, users are exposed to potential code injection attacks.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.