The Genesis Blocks WordPress plugin before 3.1.3 does not properly escape data input provided to some of its blocks, allowing using with at least contributor privileges to conduct Stored XSS attacks.
Metrics
Affected Vendors & Products
References
History
Fri, 30 May 2025 21:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Wpengine
Wpengine genesis Blocks |
|
Weaknesses | CWE-79 | |
CPEs | cpe:2.3:a:wpengine:genesis_blocks:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Wpengine
Wpengine genesis Blocks |

Status: PUBLISHED
Assigner: WPScan
Published: 2024-04-19T05:00:02.150Z
Updated: 2024-08-01T19:25:41.441Z
Reserved: 2024-03-21T13:46:20.489Z
Link: CVE-2024-2761

Updated: 2024-08-01T19:25:41.441Z

Status : Analyzed
Published: 2024-04-19T05:15:49.907
Modified: 2025-05-30T16:00:15.070
Link: CVE-2024-2761

No data.