CVE Radar Logo
CVERadar
CVE Radar Logo
CVERadar

CVE-2024-12045

High Severity
SVRS
46/100

CVSSv3
4.8/10

EPSS
0.00031/1

CVE-2024-12045 is a Stored Cross-Site Scripting (XSS) vulnerability in the Essential Blocks WordPress plugin. This flaw allows authenticated administrators to inject malicious web scripts into pages via the Google Maps block's maker title. The injected scripts execute when users visit the affected pages, posing a significant security risk.

CVE-2024-12045 affects WordPress multi-site installations and single-site installations with unfiltered_html disabled, up to plugin version 5.0.9. An attacker could exploit this vulnerability to steal sensitive information, redirect users to malicious sites, or compromise the integrity of the WordPress website. Although the CVSS score is 4.8, the SOCRadar Vulnerability Risk Score (SVRS) is 46, indicating a moderate risk. While not critical, the presence of the "In The Wild" tag suggests active exploitation, warranting prompt attention and patching to mitigate potential damage from this WordPress plugin vulnerability.

In The Wild
CVSS:3.1
AV:N
AC:L
PR:H
UI:R
S:C
C:L
I:L
A:N
2025-01-08

2025-04-17
Eye Icon
SOCRadar
AI Insight

Description

CVE-2024-12045 affects the Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress. The vulnerability is a Stored Cross-Site Scripting (XSS) flaw that arises from insufficient input sanitization and output escaping in the maker title value of the Google Maps block. This allows authenticated attackers with administrator-level access to inject arbitrary web scripts into pages, which execute whenever a user accesses an injected page.

SVRS: 38

This vulnerability, while categorized as a "medium" risk by CVSS with a score of 4.4, has an SVRS of 38. This indicates a moderate risk level requiring attention but not immediate action. However, with the vulnerability being "In The Wild," this means that it is currently being actively exploited by hackers.

Key Insights

  • Impact: Successful exploitation of this vulnerability could lead to website defacement, data theft, account takeover, and other malicious activities.
  • Affected Versions: All versions of the Essential Blocks plugin up to and including 5.0.9 are vulnerable.
  • Exploitation: The vulnerability is being actively exploited "In The Wild." This means attackers are utilizing this vulnerability to compromise WordPress sites.
  • Affected Sites: This vulnerability primarily impacts multi-site installations and installations where the unfiltered_html setting is disabled.

Mitigation Strategies

  • Update the Essential Blocks plugin: Immediately update the Essential Blocks plugin to the latest version (currently 5.0.10 or later). This patch addresses the vulnerability and is the most effective way to mitigate the risk.
  • Disable Google Maps block: As a temporary measure, consider disabling the Google Maps block within the Essential Blocks plugin until you have updated to a patched version.
  • Regularly scan for vulnerabilities: Implement a comprehensive vulnerability scanning program to regularly check for and identify vulnerabilities in your WordPress installations.
  • Implement a Web Application Firewall (WAF): Utilize a WAF to provide an extra layer of security by blocking malicious traffic targeting your website.

Additional Information

This vulnerability has been identified as "In The Wild," indicating active exploitation by hackers. This means that it is critical to take immediate action to mitigate the risk. If you have any additional questions regarding this incident, please use the 'Ask to Analyst' feature, contact SOCRadar directly, or open a support ticket for more information.

Indicators of Compromise

No IOCs found for this CVE

Exploits

No exploits found for this CVE

Enhance Your CVE Management with SOCRadar Vulnerability Intelligence
Get comprehensive CVE details, real-time notifications, and proactive threat management all in one platform.
CVE Details
Access comprehensive CVE information instantly
Real-time Tracking
Subscribe to CVEs and get instant updates
Exploit Analysis
Monitor related APT groups and threats
IOC Tracking
Analyze and track CVE-related IOCs

News

CVE-2024-12045 | Essential Blocks Plugin up to 5.0.9 on WordPress cross site scripting
vuldb.com2025-04-17
CVE-2024-12045 | Essential Blocks Plugin up to 5.0.9 on WordPress cross site scripting | A vulnerability classified as problematic has been found in Essential Blocks Plugin up to 5.0.9 on WordPress. This affects an unknown part. The manipulation leads to cross site scripting. This vulnerability is uniquely identified as CVE-2024-12045. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
rss
forum
news

Social Media

CVE-2024-12045 Stored Cross-Site Scripting in Essential Blocks WordPress Plugin 5.0.9 The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress has a Stored Cross-Site Script... https://t.co/jSOi5MhQpg
0
0
0
CVE-2024-12045 The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the maker title value… https://t.co/9JLCltOC1A
0
0
0

Affected Software

No affected software found for this CVE

References

ReferenceLink
[email protected]https://plugins.trac.wordpress.org/changeset/3210374/essential-blocks/tags/5.1.1/src/blocks/google-map/src/marker.js
[email protected]https://www.wordfence.com/threat-intel/vulnerabilities/id/b07f3ade-5f10-4621-99a2-18eeab993403?source=cve
[email protected]https://plugins.trac.wordpress.org/changeset/3210374/essential-blocks/tags/5.1.1/src/blocks/google-map/src/marker.js
[email protected]https://www.wordfence.com/threat-intel/vulnerabilities/id/b07f3ade-5f10-4621-99a2-18eeab993403?source=cve

CWE Details

CWE IDCWE NameDescription
CWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')The software does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

CVE Radar

Real-time CVE Intelligence & Vulnerability Management Platform

CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.

Get Free Vulnerability Intelligence AccessAccess real-time CVE monitoring, exploit analysis, and threat intelligence