CVE-2022-33994
https://notcve.org/view.php?id=CVE-2022-33994
The Gutenberg plugin through 13.7.3 for WordPress allows stored XSS by the Contributor role via an SVG document to the "Insert from URL" feature. NOTE: the XSS payload does not execute in the context of the WordPress instance's domain; however, analogous attempts by low-privileged users to reference SVG documents are blocked by some similar products, and this behavioral difference might have security relevance to some WordPress site administrators. El plugin Gutenberg versiones hasta 13.7.3 para WordPress, permite un ataque de tipo XSS almacenado por el rol de Colaborador por medio de un documento SVG a la funcionalidad "Insert from URL". NOTA: la carga útil de tipo XSS no es ejecutada en el contexto del dominio de la instancia de WordPress; sin embargo, los intentos análogos de usuarios poco privilegiados de hacer referencia a documentos SVG son bloqueados por algunos productos similares, y esta diferencia de comportamiento podría tener relevancia de seguridad para algunos administradores de sitios de WordPress • https://blog.jitendrapatro.me/cve-2022-33994-stored-xss-in-wordpress https://patchstack.com/articles/patchstack-weekly-svg-xss-reported-in-gutenberg • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2021-24760 – Gutenberg PDF Viewer Block < 1.0.1 - Contributor+ Stored Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2021-24760
The Gutenberg PDF Viewer Block WordPress plugin before 1.0.1 does not sanitise and escape its block, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks. El plugin Gutenberg PDF Viewer Block de WordPress versiones anteriores a 1.0.1, no sanea ni escapa de su bloque, que podría permitir a usuarios con un rol tan bajo como el de Contribuyente llevar a cabo ataques de tipo Cross-Site Scripting • https://wpscan.com/vulnerability/aebf821f-1724-4e4c-8d42-5a94e509d271 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •