Vulnerability Details CVE-2024-2392
The Blocksy Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Newsletter widget in all versions up to, and including, 2.0.31 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 28.8%
CVSS Severity
CVSS v3 Score 6.5
Products affected by CVE-2024-2392
-
cpe:2.3:a:creativethemes:blocksy_companion:-
-
cpe:2.3:a:creativethemes:blocksy_companion:1.0.1
-
cpe:2.3:a:creativethemes:blocksy_companion:1.0.3
-
cpe:2.3:a:creativethemes:blocksy_companion:1.7.32
-
cpe:2.3:a:creativethemes:blocksy_companion:1.7.33
-
cpe:2.3:a:creativethemes:blocksy_companion:1.7.35
-
cpe:2.3:a:creativethemes:blocksy_companion:1.7.36
-
cpe:2.3:a:creativethemes:blocksy_companion:1.7.37
-
cpe:2.3:a:creativethemes:blocksy_companion:1.7.38
-
cpe:2.3:a:creativethemes:blocksy_companion:1.7.39
-
cpe:2.3:a:creativethemes:blocksy_companion:1.7.40
-
cpe:2.3:a:creativethemes:blocksy_companion:1.7.41
-
cpe:2.3:a:creativethemes:blocksy_companion:1.7.43
-
cpe:2.3:a:creativethemes:blocksy_companion:1.7.44
-
cpe:2.3:a:creativethemes:blocksy_companion:1.7.45
-
cpe:2.3:a:creativethemes:blocksy_companion:1.7.46
-
cpe:2.3:a:creativethemes:blocksy_companion:1.7.47
-
cpe:2.3:a:creativethemes:blocksy_companion:1.7.49
-
cpe:2.3:a:creativethemes:blocksy_companion:1.7.50
-
cpe:2.3:a:creativethemes:blocksy_companion:1.7.51
-
cpe:2.3:a:creativethemes:blocksy_companion:1.7.52
-
cpe:2.3:a:creativethemes:blocksy_companion:1.7.53
-
cpe:2.3:a:creativethemes:blocksy_companion:1.7.54
-
cpe:2.3:a:creativethemes:blocksy_companion:1.7.55
-
cpe:2.3:a:creativethemes:blocksy_companion:1.7.56
-
cpe:2.3:a:creativethemes:blocksy_companion:1.7.57
-
cpe:2.3:a:creativethemes:blocksy_companion:1.7.58
-
cpe:2.3:a:creativethemes:blocksy_companion:1.7.59
-
cpe:2.3:a:creativethemes:blocksy_companion:1.7.60
-
cpe:2.3:a:creativethemes:blocksy_companion:1.7.61
-
cpe:2.3:a:creativethemes:blocksy_companion:1.7.62
-
cpe:2.3:a:creativethemes:blocksy_companion:1.7.63
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.0
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.1
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.10
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.11
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.12
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.13
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.14
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.15
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.16
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.17
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.18
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.19
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.2
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.20
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.21
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.22
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.23
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.24
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.25
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.26
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.27
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.29
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.30
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.31
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.32
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.33
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.34
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.35
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.36
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.37
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.38
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.4
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.40
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.41
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.42
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.43
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.44
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.45
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.46
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.47
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.48
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.49
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.5
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.51
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.52
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.53
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.54
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.55
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.56
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.57
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.58
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.59
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.6
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.6.1
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.6.2
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.6.3
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.6.4
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.60
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.61
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.62
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.63
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.64
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.65
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.66
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.67
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.68
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.69
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.7
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.7.1
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.7.2
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.7.3
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.7.4
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.7.5
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.70
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.71
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.72
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.73
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.74
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.75
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.76
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.77
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.78
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.79
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.8
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.8.1
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.8.2
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.8.3
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.8.4
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.8.5
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.8.6
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.8.7
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.8.8
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.80
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.81
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.82
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.83
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.84
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.85
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.86
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.87
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.88
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.89
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.9
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.9.1
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.9.2
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.9.3
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.9.4
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.9.5
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.9.6
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.9.7
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.9.8
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.9.9
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.90
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.91
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.92
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.93
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.94
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.95
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.96
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.97
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.98
-
cpe:2.3:a:creativethemes:blocksy_companion:1.8.99
-
cpe:2.3:a:creativethemes:blocksy_companion:1.9.0
-
cpe:2.3:a:creativethemes:blocksy_companion:1.9.1
-
cpe:2.3:a:creativethemes:blocksy_companion:1.9.10
-
cpe:2.3:a:creativethemes:blocksy_companion:1.9.11
-
cpe:2.3:a:creativethemes:blocksy_companion:1.9.2
-
cpe:2.3:a:creativethemes:blocksy_companion:1.9.3
-
cpe:2.3:a:creativethemes:blocksy_companion:1.9.4
-
cpe:2.3:a:creativethemes:blocksy_companion:1.9.5
-
cpe:2.3:a:creativethemes:blocksy_companion:1.9.6
-
cpe:2.3:a:creativethemes:blocksy_companion:1.9.7
-
cpe:2.3:a:creativethemes:blocksy_companion:1.9.8
-
cpe:2.3:a:creativethemes:blocksy_companion:1.9.9
-
cpe:2.3:a:creativethemes:blocksy_companion:2.0.0
-
cpe:2.3:a:creativethemes:blocksy_companion:2.0.1
-
cpe:2.3:a:creativethemes:blocksy_companion:2.0.10
-
cpe:2.3:a:creativethemes:blocksy_companion:2.0.11
-
cpe:2.3:a:creativethemes:blocksy_companion:2.0.12
-
cpe:2.3:a:creativethemes:blocksy_companion:2.0.13
-
cpe:2.3:a:creativethemes:blocksy_companion:2.0.14
-
cpe:2.3:a:creativethemes:blocksy_companion:2.0.15
-
cpe:2.3:a:creativethemes:blocksy_companion:2.0.16
-
cpe:2.3:a:creativethemes:blocksy_companion:2.0.17
-
cpe:2.3:a:creativethemes:blocksy_companion:2.0.18
-
cpe:2.3:a:creativethemes:blocksy_companion:2.0.19
-
cpe:2.3:a:creativethemes:blocksy_companion:2.0.2
-
cpe:2.3:a:creativethemes:blocksy_companion:2.0.20
-
cpe:2.3:a:creativethemes:blocksy_companion:2.0.21
-
cpe:2.3:a:creativethemes:blocksy_companion:2.0.22
-
cpe:2.3:a:creativethemes:blocksy_companion:2.0.23
-
cpe:2.3:a:creativethemes:blocksy_companion:2.0.24
-
cpe:2.3:a:creativethemes:blocksy_companion:2.0.25
-
cpe:2.3:a:creativethemes:blocksy_companion:2.0.26
-
cpe:2.3:a:creativethemes:blocksy_companion:2.0.27
-
cpe:2.3:a:creativethemes:blocksy_companion:2.0.28
-
cpe:2.3:a:creativethemes:blocksy_companion:2.0.29
-
cpe:2.3:a:creativethemes:blocksy_companion:2.0.3
-
cpe:2.3:a:creativethemes:blocksy_companion:2.0.30
-
cpe:2.3:a:creativethemes:blocksy_companion:2.0.31
-
cpe:2.3:a:creativethemes:blocksy_companion:2.0.4
-
cpe:2.3:a:creativethemes:blocksy_companion:2.0.5
-
cpe:2.3:a:creativethemes:blocksy_companion:2.0.6
-
cpe:2.3:a:creativethemes:blocksy_companion:2.0.7
-
cpe:2.3:a:creativethemes:blocksy_companion:2.0.8
-
cpe:2.3:a:creativethemes:blocksy_companion:2.0.9