CVE-2024-13124: Photo Gallery by 10Web < 1.8.33 - Admin+ Stored XSS
The Photo Gallery by 10Web WordPress plugin before 1.8.33 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-13124?
CVE-2024-13124 is classified as a high severity vulnerability due to its potential for allowing Stored Cross-Site Scripting attacks.
How do I fix CVE-2024-13124?
To fix CVE-2024-13124, update the Photo Gallery by 10Web plugin to version 1.8.33 or later.
Who is affected by CVE-2024-13124?
CVE-2024-13124 affects users of the Photo Gallery by 10Web WordPress plugin versions before 1.8.33.
What type of vulnerability is CVE-2024-13124?
CVE-2024-13124 is a Stored Cross-Site Scripting (XSS) vulnerability due to improper sanitization and escaping of settings.
Can administrators exploit CVE-2024-13124?
Yes, high privilege users, including administrators, can exploit CVE-2024-13124 to perform Stored Cross-Site Scripting attacks.