CVE-2024-30550: WordPress Gallery – Image and Video Gallery with Thumbnails plugin <= 2.0.3 - Reflected Cross Site Scripting (XSS) vulnerability
Published Mar 31, 2024
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdevart Responsive Image Gallery, Gallery Album allows Reflected XSS.This issue affects Responsive Image Gallery, Gallery Album: from n/a through 2.0.3.
Affected Software
3 affected components
WpDevArt Responsive Image Gallery, Gallery Album<=2.0.3
WordPress Gallery – Image and Video Gallery with Thumbnails<=2.0.3
WpDevArt Gallery Wordpress<=2.0.3
Event History
Mar 31, 2024
CVE Published
via MITRE·07:57 PM
Data Sourced
via MITRE·07:57 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-30550?
CVE-2024-30550 is classified as a reflected cross-site scripting (XSS) vulnerability.
2
How do I fix CVE-2024-30550?
To fix CVE-2024-30550, update the Responsive Image Gallery, Gallery Album plugin to the latest version beyond 2.0.3.
3
What versions are affected by CVE-2024-30550?
CVE-2024-30550 affects Responsive Image Gallery, Gallery Album versions up to and including 2.0.3.
4
What type of vulnerability is CVE-2024-30550?
CVE-2024-30550 is an improper neutralization of input during web page generation, leading to cross-site scripting.
5
Can CVE-2024-30550 be exploited remotely?
Yes, CVE-2024-30550 can be exploited remotely through reflected XSS attacks.