CVE-2024-8241
Published
CVSS v3
6.4
MEDIUM
CVSS v2
N/A
Affected
2
PROJECTS
Description
The Nova Blocks by Pixelgrade plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'align' attribute of the 'wp:separator' Gutenberg block in all versions up to, and including, 2.1.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
<p>Nova Blocks is a collection of <strong>distinctive Gutenberg blocks,</strong> committed to making your site shine like a newborn star. It is taking a design-driven approach to help you made the right decisions and showcase your content in the best shape.</p>
<h4>Positioning</h4>
<p><em>Clear and obvious, exciting and not afraid to take risks, distinctive, forward thinking.</em></p>
<ol>
<li>Obvious, not <em>confusing</em></li>
<li>Exciting, not <em>dull</em></li>
<li>Distinctive, not <em>common</em></li>
</ol>
<h4>Principles</h4>
<ol>
<li>Decisions not options</li>
<li>Purpose-driven</li>
<li>Distinctive</li>
<li>Cross-themes oriented</li>
</ol>
<h4>Tested with the following WordPress themes:</h4>
<ul>
<li><a href="https://pixelgrade.com/themes/blogging/julia-lt/" rel="nofollow ugc">Julia LT</a> <em>by Pixelgrade</em></li>
<li><a href="https://pixelgrade.com/themes/restaurants/rosa-lt/" rel="nofollow ugc">Rosa LT</a> <em>by Pixelgrade</em></li>
<li><a href="https://pixelgrade.com/themes/blogging/felt-lt/" rel="nofollow ugc">Felt LT</a> <em>by Pixelgrade</em></li>
<li><a href="https://wordpress.org/themes/twentynineteen/" rel="ugc">Twenty Nineteen</a> <em>by WordPress team</em></li>
<li><a href="https://wordpress.org/themes/storefront/" rel="ugc">Storefront</a> <em>by Automattic</em></li>
<li><a href="https://pixelgrade.com/themes/restaurants/osteria/" rel="nofollow ugc">Osteria</a> <em>by Pixelgrade</em></li>
</ul>
<p><strong>Made with love by <a href="https://pixelgrade.com/" rel="nofollow ugc">Pixelgrade</a></strong></p>
<h3>Contributing</h3>
<p>The proposed value of <strong>Open Source</strong> is that by freely sharing the code with the community, others can use, improve and contribute back to it.</p>
<p>It’s great if you’re willing to use your skills, knowledge, and experience to help further refine this project with your own improvements. We really appreciate it and you’re 💯 welcome to submit an issue or pull request on any topic.</p>
<h3>How can you help?</h3>
<ul>
<li><strong>Discovered an issue?</strong> Please report it <a href="https://github.com/pixelgrade/nova-blocks/issues/new" title="here" rel="nofollow ugc">here</a>.</li>
<li><strong>Fixed a bug?</strong> Send a <a href="https://github.com/pixelgrade/nova-blocks/pulls" title="pull request" rel="nofollow ugc">pull request</a>.</li>
<li><strong>Need a feature?</strong> Propose it <a href="https://github.com/pixelgrade/nova-blocks/issues/new" title="here" rel="nofollow ugc">here</a>.</li>
<li><strong>Have you made something great?</strong> <a href="https://github.com/pixelgrade/nova-blocks/issues/new" title="Share" rel="nofollow ugc">Share</a> it with us.</li>
</ul>
<h3>Translations</h3>
<p>You can translate Nova Blocks on <a href="https://translate.wordpress.org/projects/wp-plugins/nova-blocks" rel="nofollow ugc"><strong>translate.wordpress.org</strong></a>.</p>
<h3>Credits</h3>
<p>Unless otherwise specified, all the plugins files, scripts and images are licensed under GNU General Public License v2 or later.</p>
<p>The Nova Blocks plugin bundles the following third-party resources:</p>
<ul>
<li><a href="http://pixelgrade.github.io/rellax/" rel="nofollow ugc">jQuery Bully plugin</a> Copyright (c) 2016 Pixelgrade – License: MIT</li>
<li><a href="http://kenwheeler.github.io" rel="nofollow ugc">jQuery Slick plugin</a> Copyright (c) 2017 Ken Wheeler – License: MIT</li>
<li><a href="http://velocityjs.org/" rel="nofollow ugc">jQuery Velocity plugin</a> Copyright (c) 2014-2017 Julian Shapiro – License: MIT</li>
<li><a href="https://github.com/js-cookie/js-cookie" rel="nofollow ugc">JS Cookie</a> Copyright (c) 2018 Klaus Hartl, Fagner Brack, GitHub Contributors – License: MIT</li>
</ul>
A collection of design-driven WordPress editor blocks committed to making your site shine like a newborn star 💫