First published: Fri Nov 29 2024(Updated: )
The Photo Gallery by 10Web WordPress plugin before 1.8.31 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
10quality Post Gallery | <1.8.31 | |
10quality Post Gallery | <1.8.31 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-10704 has been classified as a high severity vulnerability due to its potential for Stored Cross-Site Scripting attacks.
To mitigate CVE-2024-10704, update the Photo Gallery by 10Web plugin to version 1.8.31 or higher.
CVE-2024-10704 affects users of the Photo Gallery by 10Web WordPress plugin versions prior to 1.8.31.
CVE-2024-10704 is a Stored Cross-Site Scripting (XSS) vulnerability.
No, CVE-2024-10704 requires high privilege users, such as administrators, to potentially exploit the vulnerability.