News & Blog Designer Pack: reflected XSS update | CVE-2024-13362

← All articles

If your site uses News & Blog Designer Pack, check the installed version and update the affected release. This article’s old title contained an extra digit in the CVE number. The correct identifier is CVE-2024-13362.

What the advisory confirms

Patchstack lists versions through 3.4.9 as affected and 3.4.11 as the patched version for this issue. It reports a CVSS score of 6.1 and separately assigns a low operational priority. The previous “Critical” headline blurred those different assessments. Successful exploitation requires a user to interact with a crafted link or page. Read the plugin-specific advisory.

The official CVE covers a Freemius SDK issue affecting multiple bundled products. Use the version entry for your actual plugin, rather than treating the SDK version as the WordPress plugin version. Review the CVE record.

What to do on your site

  1. Confirm that the installed plugin is News & Blog Designer Pack, then record its version.
  2. Install the vendor’s current supported update; 3.4.11 is the historical fix for this specific vulnerability.
  3. Test the post grid, slider and other layouts used by your site.
  4. If someone opened a suspicious administrative link, review that account’s activity and investigate unexpected changes.

Avoid misleading assurances

This advisory does not establish that every installation has been compromised. It also does not prove that a generic firewall rule will block this DOM-based issue. Use the plugin update and vendor guidance as the basis for remediation, and assess any suspected incident separately.