First published: Thu Jan 02 2025(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Contest Gallery Contest Gallery allows Stored XSS.This issue affects Contest Gallery: from n/a through 24.0.3.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Contest Gallery | <=24.0.3 | |
WordPress Contest Gallery | <=24.0.3 |
Update the WordPress Contest Gallery plugin to the latest available version (at least 24.0.4).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-56237 is classified as a Stored Cross-site Scripting (XSS) vulnerability in Contest Gallery.
To fix CVE-2024-56237, update Contest Gallery to version 24.0.4 or later.
CVE-2024-56237 affects all versions of Contest Gallery up to and including 24.0.3.
The potential impacts of CVE-2024-56237 include unauthorized script execution, which can lead to data theft and user session hijacking.
Users and administrators of the Contest Gallery plugin for WordPress versions up to 24.0.3 are impacted by CVE-2024-56237.