← Back

CVE-2024-9645

nvd nist
Published: May 15, 2025Modified: Jun 4, 2025

JSON object

Loading...
5.4
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.3 / Impact: 2.7
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

The Post Grid, Posts Slider, Posts Carousel, Post Filter, Post Masonry WordPress plugin before 2.2.93 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

Affected (1)

1 product
Post Grid
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 2.2.93

References (1)

Source: contact@wpscan.com
ExploitThird Party Advisory

Timeline

No history available yet.