CVE-2024-3901
Last modified
CVE-2024-3901 is a medium-severity vulnerability rated 6.8/10 on the CVSS scale. The Genesis Blocks WordPress plugin through 3.1.3 does not properly escape attributes provided to some of its custom blocks, making it possible for users allowed to write posts (like those with the contributor role) to conduct Stored XSS attacks.. EPSS estimates a 0.47% chance of exploitation in the next 30 days.
Description
The Genesis Blocks WordPress plugin through 3.1.3 does not properly escape attributes provided to some of its custom blocks, making it possible for users allowed to write posts (like those with the contributor role) to conduct Stored XSS attacks.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Wpengine | Genesis Blocks | < 3.1.4 |
References
- https://wpscan.com/vulnerability/9502e1ac-346e-4431-90a6-61143d2df37b/Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2024-3901?
How severe is CVE-2024-3901?
How do I fix CVE-2024-3901?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-3900Out-of-bounds array write in Xpdf 4.05 and earlier, triggere…5.5
- CVE-2024-39000adolph_dudu ratio-swiper v0.0.2 was discovered to contain a …6.5
- CVE-2024-39001ag-grid-enterprise v31.3.2 was discovered to contain a proto…6.3
- CVE-2024-39002rjrodger jsonic-next v2.12.1 was discovered to contain a pro…6.3
- CVE-2024-39003amoyjs amoy common v1.0.10 was discovered to contain a proto…7.3
- CVE-2024-39008robinweser fast-loops v1.1.3 was discovered to contain a pro…10
- CVE-2024-39010chase-moskal snapstate v0.0.9 was discovered to contain a pr…9.8
- CVE-2024-39011Prototype Pollution in chargeover redoc v2.0.9-rc.69 allows …9.8
- CVE-2024-39012ais-ltd strategyen v0.4.0 was discovered to contain a protot…9.8
- CVE-2024-390132o3t-utility v0.1.2 was discovered to contain a prototype po…9.8
- CVE-2024-39014ahilfoley cahil/utils v2.3.2 was discovered to contain a pro…9.8
- CVE-2024-39015cafebazaar hod v0.4.14 was discovered to contain a prototype…9.8
Are you affected by CVE-2024-3901?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
