
CVE-2024-32586 – WordPress Gutenberg Block Editor Toolkit plugin <= 1.40.4 - Cross Site Scripting (XSS) vulnerability
https://notcve.org/view.php?id=CVE-2024-32586
18 Apr 2024 — Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Munir Kamal Gutenberg Block Editor Toolkit allows Stored XSS.This issue affects Gutenberg Block Editor Toolkit: from n/a through 1.40.4. La vulnerabilidad de neutralización inadecuada de la entrada durante la generación de páginas web ('cross-site Scripting') en Munir Kamal Gutenberg Block Editor Toolkit permite almacenar XSS. Este problema afecta al Gutenberg Block Editor Toolkit: desde n/a hasta 1.40.4. • https://patchstack.com/database/vulnerability/block-options/wordpress-gutenberg-block-editor-toolkit-plugin-1-40-4-cross-site-scripting-xss-vulnerability?_s_id=cve • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2022-33994
https://notcve.org/view.php?id=CVE-2022-33994
30 Jul 2022 — The Gutenberg plugin through 13.7.3 for WordPress allows stored XSS by the Contributor role via an SVG document to the "Insert from URL" feature. NOTE: the XSS payload does not execute in the context of the WordPress instance's domain; however, analogous attempts by low-privileged users to reference SVG documents are blocked by some similar products, and this behavioral difference might have security relevance to some WordPress site administrators. El plugin Gutenberg versiones hasta 13.7.3 para WordPress, ... • https://blog.jitendrapatro.me/cve-2022-33994-stored-xss-in-wordpress • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2021-24760 – Gutenberg PDF Viewer Block < 1.0.1 - Contributor+ Stored Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2021-24760
20 Sep 2021 — The Gutenberg PDF Viewer Block WordPress plugin before 1.0.1 does not sanitise and escape its block, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks. El plugin Gutenberg PDF Viewer Block de WordPress versiones anteriores a 1.0.1, no sanea ni escapa de su bloque, que podría permitir a usuarios con un rol tan bajo como el de Contribuyente llevar a cabo ataques de tipo Cross-Site Scripting • https://wpscan.com/vulnerability/aebf821f-1724-4e4c-8d42-5a94e509d271 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •