CVE-2024-9601

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Feb 14, 2025
Updated: Feb 25, 2025
CWE ID 79

Summary

CVE-2024-9601 is a stored Cross-Site Scripting (XSS) vulnerability affecting the Qubely – Advanced Gutenberg Blocks plugin for WordPress. Versions up to and including 1.8.12 are vulnerable to this issue. This flaw, caused by insufficient input sanitization and output escaping, allows authenticated attackers with Contributor-level access and above to inject arbitrary web scripts. These scripts will execute whenever a user accesses an injected page. This vulnerability poses a significant security risk, as it enables attackers to gain unauthorized control over WordPress websites. It is crucial for users to update their plugin as soon as possible to mitigate this threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share