CVE-2024-10144: Photo Gallery, Images, Slider in Rbs Image Gallery < 3.2.22 - Contributor+ Stored XSS
The Photo Gallery, Images, Slider in Rbs Image Gallery WordPress plugin before 3.2.22 does not sanitise and escape some of its settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-10144?
CVE-2024-10144 is considered a high severity vulnerability due to its potential for Stored Cross-Site Scripting attacks.
How do I fix CVE-2024-10144?
To fix CVE-2024-10144, update the Rbs Image Gallery plugin to version 3.2.22 or later.
Who is affected by CVE-2024-10144?
CVE-2024-10144 affects users of the Rbs Image Gallery and Robosoft Robo Gallery WordPress plugins prior to version 3.2.22.
What type of vulnerability is CVE-2024-10144?
CVE-2024-10144 is a Stored Cross-Site Scripting (XSS) vulnerability.
Can contributor users exploit CVE-2024-10144?
Yes, high privilege users, such as contributors, may exploit CVE-2024-10144 to perform Stored Cross-Site Scripting attacks.