CVE-2024-9073
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Published Sep 25, 2024
Updated: Oct 2, 2024
CWE ID 79
Summary
CVE-2024-9073 is a Stored Cross-Site Scripting (XSS) vulnerability affecting the GutenGeek Free Gutenberg Blocks plugin for WordPress. Versions up to and including 1.1.3 are susceptible to this issue. The flaw is caused by insufficient input sanitization and output escaping during SVG file uploads. This vulnerability enables authenticated attackers, with Author-level access and above, to inject malicious web scripts into pages. Execution of these scripts occurs when a user accesses the SVG file, posing a significant security risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.