CVE-2024-8760

CVSS 3.1 Score 5.3 of 10 (medium)

Details

Published Oct 12, 2024
Updated: Oct 15, 2024
CWE ID 94

Summary

CVE-2024-8760 is a vulnerability affecting the Stackable – Page Builder Gutenberg Blocks plugin for WordPress. This issue allows unauthenticated attackers to inject malicious CSS code into comments. This can lead to data exfiltration, including the theft of admin nonces, which can be used for Cross-Site Request Forgery (CSRF) attacks. The impact is limited to the time window of the vulnerability's exploitation, but the presence of other plugins may expose additional nonces, increasing the risk for plugins that don't adequately protect AJAX actions or other actions accessible to lower-privileged users.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share