CVE-2024-13400
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Published Jan 30, 2025
Updated: Jan 31, 2025
CWE ID 79
Summary
CVE-2024-13400: The Kona Gallery Block plugin for WordPress contains a Stored Cross-Site Scripting (XSS) vulnerability. This issue, affecting all versions up to 1.7, is located in the "Kona: Instagram for Gutenberg" Block's "align" attribute. The flaw is due to inadequate input sanitization and output escaping, which grants authenticated attackers, including those with Contributor-level access and above, the ability to inject malicious web scripts. These scripts will execute whenever a user accesses a manipulated page.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share