"value":"The Blockspare: Gutenberg Blocks & Patterns for Blogs, Magazines, Business Sites \u2013 Post Grids, Sliders, Carousels, Counters, Page Builder & Starter Site Imports, No Coding Needed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in the \u2018blockspare_render_social_sharing_block\u2019 function in all versions up to, and including, 3.2.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page."
}
]
},
"problemtype":{
"problemtype_data":[
{
"description":[
{
"lang":"eng",
"value":"CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
"cweId":"CWE-79"
}
]
}
]
},
"affects":{
"vendor":{
"vendor_data":[
{
"vendor_name":"blockspare",
"product":{
"product_data":[
{
"product_name":"Blockspare: Gutenberg Blocks & Patterns for Blogs, Magazines, Business Sites \u2013 Post Grids, Sliders, Carousels, Counters, Page Builder & Starter Site Imports, No Coding Needed",