CVE-2024-2762: FooGallery < 2.4.15 - Author+ Stored XSS
The FooGallery WordPress plugin before 2.4.15, foogallery-premium WordPress plugin before 2.4.15 does not validate and escape some of its Gallery settings before outputting them back in the page, which could allow users with a role as low as Author to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admin
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-2762?
CVE-2024-2762 is considered to have a medium severity rating due to its potential for stored cross-site scripting attacks.
How do I fix CVE-2024-2762?
To fix CVE-2024-2762, you should update the FooGallery plugin to version 2.4.15 or later.
Who is affected by CVE-2024-2762?
Users with the FooGallery plugin version prior to 2.4.15, including the premium version, are affected by CVE-2024-2762.
What type of vulnerability is CVE-2024-2762?
CVE-2024-2762 is a stored cross-site scripting vulnerability that affects the FooGallery WordPress plugins.
How can CVE-2024-2762 be exploited?
CVE-2024-2762 can be exploited by users with author-level permissions who can inject malicious scripts into gallery settings.