CVE-2024-9601
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Summary
CVE-2024-9601 is a stored Cross-Site Scripting (XSS) vulnerability affecting the Qubely – Advanced Gutenberg Blocks plugin for WordPress. Versions up to and including 1.8.12 are vulnerable to this issue. This flaw, caused by insufficient input sanitization and output escaping, allows authenticated attackers with Contributor-level access and above to inject arbitrary web scripts. These scripts will execute whenever a user accesses an injected page. This vulnerability poses a significant security risk, as it enables attackers to gain unauthorized control over WordPress websites. It is crucial for users to update their plugin as soon as possible to mitigate this threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Themeum Qubely
Affected Vendors
- THEMEUM