CVE-2024-6884

MEDIUM

Gutenberg Blocks with AI by Kadence WP < 3.2.39 - Stored Cross-Site Scripting via Block Options

Title source: llm
STIX 2.1

Description

The Gutenberg Blocks with AI by Kadence WP WordPress plugin before 3.2.39 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

References (1)

Core 1
Core References
Exploit, Third Party Advisory exploit vdb-entry technical-description
https://wpscan.com/vulnerability/1768de0c-e4ea-4c98-abf1-7ac805f214b8/

Scores

CVSS v3 5.4
EPSS 0.0039
EPSS Percentile 31.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
kadencewp/gutenberg_blocks_with_ai < 3.2.39
Published Aug 08, 2024
Tracked Since Feb 18, 2026