CVE-2024-44043: WordPress Photo Gallery by 10Web plugin <= 1.8.27 - Cross Site Scripting (XSS) vulnerability
Published Oct 6, 2024
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 10Web Photo Gallery by 10Web photo-gallery allows Stored XSS.This issue affects Photo Gallery by 10Web: from n/a through <= 1.8.27.
Affected Software
3 affected components
10web Photo Gallery<=1.8.27
10web Photo Gallery by 10Web<=1.8.27
10web Photo Gallery Wordpress<1.8.28
Remediation
Information
Update to 1.8.28 or a higher version.
Event History
Oct 6, 2024
CVE Published
via MITRE·11:58 AM
Data Sourced
via MITRE·11:58 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-44043?
The severity of CVE-2024-44043 is classified as a medium risk due to the potential for Stored XSS attacks.
2
How do I fix CVE-2024-44043?
To fix CVE-2024-44043, update the 10Web Photo Gallery plugin to version 1.8.28 or higher.
3
What does CVE-2024-44043 affect?
CVE-2024-44043 affects versions of 10Web Photo Gallery up to and including 1.8.27.
4
What type of vulnerability is CVE-2024-44043?
CVE-2024-44043 is a cross-site scripting (XSS) vulnerability that allows attackers to inject malicious scripts.
5
Is CVE-2024-44043 a stored or reflected XSS vulnerability?
CVE-2024-44043 is classified as a Stored XSS vulnerability, meaning the malicious script can be stored on the server.