CVE-2024-1791
Last modified
CVE-2024-1791 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. The CodeMirror Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Code Mirror block in all versions up to, and including, 1.2.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.. EPSS estimates a 0.44% chance of exploitation in the next 30 days.
Description
The CodeMirror Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Code Mirror block in all versions up to, and including, 1.2.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Vickyagravat | Codemirror Blocks | < 2.0.0 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2024-1791?
How severe is CVE-2024-1791?
How do I fix CVE-2024-1791?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-1785The Contests by Rewards Fuel plugin for WordPress is vulnera…5.4
- CVE-2024-1786** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was c…7.5
- CVE-2024-1787The Contests by Rewards Fuel plugin for WordPress is vulnera…6.4
- CVE-2024-1788Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMB…
- CVE-2024-1789The WP SMTP plugin for WordPress is vulnerable to SQL Inject…7.2
- CVE-2024-1790The WordPress Infinite Scroll – Ajax Load More plugin for Wo…4.9
- CVE-2024-1792The CMB2 plugin for WordPress is vulnerable to PHP Object In…7.5
- CVE-2024-1793The AWeber – Free Sign Up Form and Landing Page Builder Plug…7.2
- CVE-2024-1794The Forminator plugin for WordPress is vulnerable to Stored …6.1
- CVE-2024-1795The HUSKY – Products Filter for WooCommerce Professional plu…8.8
- CVE-2024-1796The HUSKY – Products Filter for WooCommerce Professional plu…5.4
- CVE-2024-1797The WP ULike – Most Advanced WordPress Marketing Toolkit plu…8.8
Are you affected by CVE-2024-1791?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
