CVE-2024-29832: WordPress Photo Gallery Plugin <= 1.8.21 Unauthenticated Reflected Cross Site Scripting in GalleryBox current_url
The currenturl parameter of the AJAX call to the GalleryBox action of admin-ajax.php is vulnerable to reflected Cross Site Scripting. The value of the currenturl parameter is embedded within an existing JavaScript within the response allowing arbitrary JavaScript to be inserted and executed. No authentication is required to exploit this issue. Note that other parameters within a AJAX call, such as imageid, must be valid for this vulnerability to be successfully exploited.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-29832?
CVE-2024-29832 is rated as a medium severity vulnerability due to the potential for reflected Cross Site Scripting.
How do I fix CVE-2024-29832?
To fix CVE-2024-29832, update the WordPress Photo Gallery Plugin to version 1.8.22 or later.
What type of vulnerability is CVE-2024-29832?
CVE-2024-29832 is a reflected Cross Site Scripting (XSS) vulnerability that allows arbitrary JavaScript insertion.
Which software versions are affected by CVE-2024-29832?
CVE-2024-29832 affects the WordPress Photo Gallery Plugin up to version 1.8.21.
How does CVE-2024-29832 impact users?
CVE-2024-29832 can lead to session hijacking and malicious content execution in the context of the user’s browser.