CVE-2024-10939: Image Widget < 4.4.11 - Admin+ Stored XSS
The Image Widget WordPress plugin before 4.4.11 does not sanitise and escape some of its Image Widget settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-10939?
CVE-2024-10939 is considered a high severity vulnerability due to the potential for Stored Cross-Site Scripting attacks.
How do I fix CVE-2024-10939?
To fix CVE-2024-10939, update the Image Widget plugin to version 4.4.11 or later.
Who is affected by CVE-2024-10939?
CVE-2024-10939 affects WordPress users who have the Image Widget plugin installed prior to version 4.4.11.
What type of vulnerability is CVE-2024-10939?
CVE-2024-10939 is a Stored Cross-Site Scripting vulnerability.
Can only admins exploit CVE-2024-10939?
Yes, CVE-2024-10939 allows high privilege users, such as admins, to exploit the vulnerability.