First published: Mon Mar 24 2025(Updated: )
The Photo Gallery by 10Web WordPress plugin before 1.8.33 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
10quality Post Gallery | <1.8.33 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-13124 is classified as a high severity vulnerability due to its potential for allowing Stored Cross-Site Scripting attacks.
To fix CVE-2024-13124, update the Photo Gallery by 10Web plugin to version 1.8.33 or later.
CVE-2024-13124 affects users of the Photo Gallery by 10Web WordPress plugin versions before 1.8.33.
CVE-2024-13124 is a Stored Cross-Site Scripting (XSS) vulnerability due to improper sanitization and escaping of settings.
Yes, high privilege users, including administrators, can exploit CVE-2024-13124 to perform Stored Cross-Site Scripting attacks.