CVE-2024-2729: Themeisle Otter Blocks
Medium severity, CVSS 6.1. EPSS: 0.4% chance of exploitation in the next 30 days.
The Otter Blocks WordPress plugin before 2.6.6 does not properly escape its mainHeadings blocks' attribute before appending it to the final rendered block, allowing contributors to conduct Stored XSS attacks.
Affected products
- Themeisle Otter Blocks: before 2.6.6 (fixed in 2.6.6)
Published 2024-04-18. Last modified 2026-06-17.