CVE-2023-6924: Photo Gallery by 10Web <= 1.8.18 - Authenticated (Administrator+) Stored Cross-Site Scripting via Widget
The Photo Gallery by 10Web plugin for WordPress is vulnerable to Stored Cross-Site Scripting via widgets in versions up to, and including, 1.8.18 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with administrator-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. It can also be exploited with a contributor-level permission with a page builder plugin.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2023-6924?
The severity of CVE-2023-6924 is high due to the potential for authenticated attackers to execute malicious scripts.
How do I fix CVE-2023-6924?
To fix CVE-2023-6924, update the Photo Gallery by 10Web plugin to version 1.8.19 or later.
Who is affected by CVE-2023-6924?
CVE-2023-6924 affects users of the Photo Gallery by 10Web plugin for WordPress in versions up to and including 1.8.18.
What type of vulnerability is CVE-2023-6924?
CVE-2023-6924 is a Stored Cross-Site Scripting vulnerability.
What causes CVE-2023-6924?
CVE-2023-6924 is caused by insufficient input sanitization and output escaping on user-supplied attributes.