CVE-2024-3710: Image Photo Gallery Final Tiles Grid < 3.6.0 - Contributor+ Stored XSS
The Image Photo Gallery Final Tiles Grid WordPress plugin before 3.6.0 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admin
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-3710?
CVE-2024-3710 is rated as a high-severity vulnerability due to its potential for Stored Cross-Site Scripting attacks.
How do I fix CVE-2024-3710?
To fix CVE-2024-3710, update the Image Photo Gallery Final Tiles Grid plugin to version 3.6.0 or later.
Who is affected by CVE-2024-3710?
Users of the Image Photo Gallery Final Tiles Grid plugin for WordPress with versions prior to 3.6.0 are affected by CVE-2024-3710.
What types of attacks can CVE-2024-3710 facilitate?
CVE-2024-3710 can facilitate Stored Cross-Site Scripting (XSS) attacks, allowing malicious scripts to be executed.
What roles can exploit CVE-2024-3710?
CVE-2024-3710 can be exploited by users with a role as low as contributor.