CVE-2024-49696: WordPress Photo Gallery, Images, Slider in Rbs Image Gallery plugin <= 3.2.21 - Cross Site Scripting (XSS) vulnerability
Published Oct 24, 2024
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in robosoft Robo Gallery robo-gallery allows Stored XSS.This issue affects Robo Gallery: from n/a through <= 3.2.21.
Affected Software
1 affected component
robosoft Robo Gallery Wordpress<3.2.22
Remediation
Information
Update to 3.2.22 or a higher version.
Event History
Oct 24, 2024
CVE Published
via MITRE·12:29 PM
Data Sourced
via MITRE·12:29 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-49696?
CVE-2024-49696 is classified as a high severity vulnerability due to the potential for stored XSS attacks.
2
How do I fix CVE-2024-49696?
To fix CVE-2024-49696, update the Robo Gallery plugin to version 3.2.22 or later.
3
What type of vulnerability is CVE-2024-49696?
CVE-2024-49696 involves improper neutralization of input during web page generation, leading to stored XSS vulnerabilities.
4
Which versions of Robo Gallery are affected by CVE-2024-49696?
CVE-2024-49696 affects Robo Gallery versions up to and including 3.2.21.
5
Can CVE-2024-49696 affect my website?
Yes, if your website is using an affected version of Robo Gallery, it could be vulnerable to attacks leveraging CVE-2024-49696.