CVE-2024-10867

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Jan 31, 2025
CWE ID 79

Summary

CVE-2024-10867 is a stored Cross-Site Scripting (XSS) vulnerability affecting the Borderless plugin for WordPress, used in Elementor & Gutenberg. Versions up to 1.5.9 are vulnerable. This issue stems from insufficient sanitization and output escaping of SVG file uploads. Attackers with Author-level access and above can exploit this, injecting malicious scripts that execute whenever a user accesses the infected SVG file. Consequently, users are exposed to potential code injection attacks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share