CVE-2024-13384: Photo Gallery, Images, Slider in Rbs Image Gallery < 3.2.24 - Admin+ Stored XSS
The Photo Gallery, Images, Slider in Rbs Image Gallery WordPress plugin before 3.2.24 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-13384?
CVE-2024-13384 has a high severity rating due to its potential for Stored Cross-Site Scripting attacks.
How do I fix CVE-2024-13384?
To fix CVE-2024-13384, update the Rbs Image Gallery plugin to version 3.2.24 or later.
Who is affected by CVE-2024-13384?
CVE-2024-13384 affects users of the Rbs Image Gallery and Robosoft Robo Gallery plugins before version 3.2.24.
Can CVE-2024-13384 be exploited by low privilege users?
No, CVE-2024-13384 requires high privilege users, such as administrators, to exploit the vulnerability.
What are the consequences of CVE-2024-13384?
Exploiting CVE-2024-13384 can lead to unauthorized script execution and data theft on affected WordPress sites.