CVE-2023-24004: WordPress Image and Video Lightbox, Image PopUp Plugin <= 2.1.5 is vulnerable to Cross Site Scripting (XSS)
Published Apr 6, 2023
·Updated
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WPdevart Image and Video Lightbox, Image PopUp plugin <= 2.1.5 versions.
Affected Software
1 affected component
WpDevArt Download Image And Video Lightbox\, Image Popup Wordpress<2.1.6
Remediation
Information
Update to 2.1.6 or a higher version.
Event History
Apr 6, 2023
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2023-24004?
CVE-2023-24004 is an authentication bypass vulnerability in WPdevart Image and Video Lightbox, Image PopUp plugin with versions up to 2.1.6.
2
How severe is CVE-2023-24004?
CVE-2023-24004 has a severity rating of 4.8 (medium).
3
What is the affected software for CVE-2023-24004?
The affected software for CVE-2023-24004 is WPdevart Download Image And Video Lightbox, Image Popup plugin versions up to 2.1.6.
4
What is the Common Weakness Enumeration (CWE) for CVE-2023-24004?
The Common Weakness Enumeration (CWE) for CVE-2023-24004 is CWE-79 (Cross-Site Scripting).
5
How can I fix CVE-2023-24004?
To fix CVE-2023-24004, update WPdevart Image and Video Lightbox, Image PopUp plugin to version 2.1.6 or higher.