CVE-2024-3276: FooBox (Free and Premium) < 2.7.28 - Admin+ Stored XSS
The Lightbox & Modal Popup WordPress Plugin WordPress plugin before 2.7.28, foobox-image-lightbox-premium WordPress plugin before 2.7.28 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-3276?
CVE-2024-3276 is classified as a high severity vulnerability that could allow stored cross-site scripting by high privilege users.
How do I fix CVE-2024-3276?
To fix CVE-2024-3276, update the Foobox WordPress plugin to version 2.7.28 or later, which includes the necessary security patches.
Who is affected by CVE-2024-3276?
CVE-2024-3276 affects users of the Foobox and foobox-image-lightbox-premium WordPress plugins prior to version 2.7.28.
What type of vulnerability is CVE-2024-3276?
CVE-2024-3276 is a stored cross-site scripting (XSS) vulnerability that arises from improper sanitization and escaping of plugin settings.
Can low privilege users exploit CVE-2024-3276?
No, only high privilege users such as admins can exploit CVE-2024-3276 due to the nature of the vulnerability.