First published: Wed Mar 27 2024(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Portfolio Gallery – Image Gallery Plugin allows Stored XSS.This issue affects Portfolio Gallery – Image Gallery Plugin: from n/a through 1.5.6.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Portfolio Gallery Image Gallery Plugin | <=1.5.6 | |
WordPress Portfolio Gallery | <=1.5.6 |
Update to 1.5.7 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-29769 is classified as a Stored Cross-Site Scripting (XSS) vulnerability.
To fix CVE-2024-29769, update the Portfolio Gallery – Image Gallery Plugin to a version later than 1.5.6.
CVE-2024-29769 affects versions of the Portfolio Gallery – Image Gallery Plugin up to and including 1.5.6.
CVE-2024-29769 can be exploited to perform stored XSS attacks, allowing attackers to inject malicious scripts into web pages.
Yes, CVE-2024-29769 involves improper neutralization of user input during web page generation, which is a key factor in XSS vulnerabilities.