CVE-2024-37519: WordPress Premium Blocks – Gutenberg Blocks for WordPress plugin <= 2.1.27 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Leap13 Premium Blocks – Gutenberg Blocks for WordPress premium-blocks-for-gutenberg.This issue affects Premium Blocks – Gutenberg Blocks for WordPress: from n/a through <= 2.1.27.
Security readout for executives and security teams
Plain-English summary
This CVE affects the WordPress Premium Blocks Gutenberg plugin through version 2.1.27. A logged-in user could inject script into generated pages, but another user must interact with affected content. Business impact is usually site trust, content integrity, and possible user-session risk rather than server takeover.
Executive priority
Treat as a moderate-priority web content risk. Prioritize externally facing WordPress sites, sites with many contributors, and sites handling authenticated user sessions or customer trust-sensitive content.
Technical view
The issue is CWE-79 cross-site scripting from improper input neutralization during page generation in Leap13 premium-blocks-for-gutenberg. CVSS 3.1 is 6.5 with network access, low complexity, low privileges, required user interaction, changed scope, and low confidentiality, integrity, and availability impact.
Likely exposure
Exposure is limited to WordPress sites running Premium Blocks – Gutenberg Blocks for WordPress versions up to 2.1.27. Risk is higher where untrusted or lightly trusted users can edit posts, pages, or blocks.
Exploitation context
The supplied sources do not report active exploitation, and KEV is false. The CVSS vector indicates exploitation requires a low-privileged authenticated actor and user interaction, consistent with a stored or rendered XSS scenario.
Researcher notes
The bundle names versions through 2.1.27, but the affected object also shows an imprecise version value. No patch version, exploit proof, or detailed vulnerable parameter is provided, so validation should focus on asset presence, role exposure, and vendor guidance.
Mitigation direction
Inventory WordPress sites for premium-blocks-for-gutenberg versions up to 2.1.27.
Check Leap13 or Patchstack guidance for a fixed version or official workaround.
Restrict block and content editing access to trusted users until remediated.
Disable or remove the plugin if unused or unsupported.
Review affected content for unexpected scripts or suspicious block markup.
Validation and detection
Confirm the plugin slug and exact installed version across WordPress assets.
Identify users and roles able to create or edit affected Gutenberg blocks.
Review content change history for suspicious edits to pages or posts.
Recheck plugin status against vendor or Patchstack guidance after remediation.
Confirm suspicious content removal is reflected in published and cached pages.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · medium confidence lookup
CWE-79: User-session and phishing behavior lookup
Client-side and session-facing weaknesses should be reviewed alongside initial-access and user-execution behaviors. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
CWE-79 · source CWE mapping
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.