← back
CVE-2024-2729

Otter Blocks < 2.6.6 - Contributor+ Stored XSS

CVSS 6.1 MEDIUMEPSS 0.4%
The Otter Blocks WordPress plugin before 2.6.6 does not properly escape its mainHeadings blocks' attribute before appending it to the final rendered block, allowing contributors to conduct Stored XSS attacks.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Affected products
Unknown · Otter Blocks

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →