CVE-2024-2729

The Otter Blocks WordPress plugin before 2.6.6 does not properly escape its mainHeadings blocks' attribute before appending it to the final rendered block, allowing contributors to conduct Stored XSS attacks.
Configurations

Configuration 1 (hide)

cpe:2.3:a:themeisle:otter_blocks:*:*:*:*:*:wordpress:*:*

History

No history.

Information

Published : 2024-04-18 05:15

Updated : 2025-05-08 20:33


NVD link : CVE-2024-2729

Mitre link : CVE-2024-2729

CVE.ORG link : CVE-2024-2729


JSON object : View

Products Affected

themeisle

  • otter_blocks
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')