CVE-2024-29809: WordPress Photo Gallery Plugin <= 1.8.21 Reflected Cross Site Scripting in editimage_bwg image_url
The imageurl parameter of the AJAX call to the editimagebwg action of admin-ajax.php is vulnerable to reflected Cross Site Scripting. The value of the imageurl parameter is embedded within an existing JavaScript within the response allowing arbitrary JavaScript to be inserted and executed. The attacker must target a an authenticated user with permissions to access this component to exploit this issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-29809?
CVE-2024-29809 is classified as a medium severity vulnerability due to its potential for reflected Cross Site Scripting.
How can I fix CVE-2024-29809?
To fix CVE-2024-29809, ensure that you update the WordPress Photo Gallery Plugin to the latest version available.
What does CVE-2024-29809 affect?
CVE-2024-29809 affects the WordPress Photo Gallery Plugin versions up to and including 1.8.21.
Is CVE-2024-29809 a local or remote vulnerability?
CVE-2024-29809 is a remote vulnerability that can be exploited through manipulated AJAX requests.
What types of attacks can CVE-2024-29809 lead to?
CVE-2024-29809 can lead to arbitrary JavaScript execution on the affected website, enabling attackers to perform actions on behalf of users.