CVE-2024-5595

MEDIUM

Wpdeveloper Essential Blocks < 4.7.0 - XSS

Title source: rule

Description

The Essential Blocks WordPress plugin before 4.7.0 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

Scores

CVSS v3 5.4
EPSS 0.0030
EPSS Percentile 52.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Classification

CWE
CWE-79
Status published

Affected Products (1)

wpdeveloper/essential_blocks < 4.7.0

Timeline

Published Aug 02, 2024
Tracked Since Feb 18, 2026