CVE-2024-5968: Photo Gallery by 10Web <= 1.8.27 - Admin+ Stored XSS
The Photo Gallery by 10Web WordPress plugin before 1.8.28 does not properly sanitise and escape some of its Gallery settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup)
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-5968?
CVE-2024-5968 has a moderate severity level due to its potential for Stored Cross-Site Scripting attacks.
How do I fix CVE-2024-5968?
To fix CVE-2024-5968, update the Photo Gallery by 10Web plugin to version 1.8.28 or later.
Who is affected by CVE-2024-5968?
CVE-2024-5968 affects installations of the Photo Gallery by 10Web plugin prior to version 1.8.28.
What type of vulnerability is CVE-2024-5968?
CVE-2024-5968 is classified as a Stored Cross-Site Scripting (XSS) vulnerability.
Can administrators exploit CVE-2024-5968?
Yes, high privilege users, such as administrators, can exploit CVE-2024-5968 to perform attacks even when the unfiltered_html capability is disallowed.