CVE-2024-2744: Nextgen Gallery < 3.59.1 - Admin+ Stored XSS
The NextGEN Gallery WordPress plugin before 3.59.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfilteredhtml is disallowed
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-2744?
CVE-2024-2744 has a high severity rating due to the potential for Cross-Site Scripting (XSS) attacks affecting high privilege users.
How do I fix CVE-2024-2744?
To fix CVE-2024-2744, upgrade the NextGEN Gallery plugin to version 3.59.1 or later.
Who is affected by CVE-2024-2744?
CVE-2024-2744 primarily affects users of the NextGEN Gallery plugin for WordPress versions before 3.59.1.
What types of attacks can CVE-2024-2744 enable?
CVE-2024-2744 can enable Cross-Site Scripting (XSS) attacks, allowing malicious scripts to be executed in the context of a user's browser.
Is unfiltered_html setting sufficient protection against CVE-2024-2744?
No, the unfiltered_html setting is not sufficient protection against CVE-2024-2744, as it can still allow XSS vulnerabilities to be exploited by high privilege users.