CVE-2024-56237: WordPress Contest Gallery plugin <= 24.0.3 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery contest-gallery allows Stored XSS.This issue affects Contest Gallery: from n/a through <= 24.0.3.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-56237?
CVE-2024-56237 is classified as a Stored Cross-site Scripting (XSS) vulnerability in Contest Gallery.
How do I fix CVE-2024-56237?
To fix CVE-2024-56237, update Contest Gallery to version 24.0.4 or later.
What software versions are affected by CVE-2024-56237?
CVE-2024-56237 affects all versions of Contest Gallery up to and including 24.0.3.
What are the potential impacts of CVE-2024-56237?
The potential impacts of CVE-2024-56237 include unauthorized script execution, which can lead to data theft and user session hijacking.
Who is impacted by CVE-2024-56237?
Users and administrators of the Contest Gallery plugin for WordPress versions up to 24.0.3 are impacted by CVE-2024-56237.