WordPress Plugin Vulnerabilities
Gutenberg < 14.3.1 - Multiple Stored XSS
Description
The plugin does not escape data from some blocks before outputting ti back in pages, which could lead to Stored XSS issues.
Affected blocks: Search, Feature Image, RSS and Widget
Affects Plugins
References
Classification
Type
XSS
OWASP top 10
CWE
CVSS
Miscellaneous
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2022-10-17 (about 3 years ago)
Added
2022-10-18 (about 3 years ago)
Last Updated
2022-10-18 (about 3 years ago)