First published: Wed Oct 09 2024(Updated: )
The Photo Gallery by 10Web WordPress plugin before 1.8.28 does not properly sanitise and escape some of its Gallery settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
10quality Post Gallery | <1.8.28 | |
10quality Post Gallery | <1.8.28 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-5968 has a moderate severity level due to its potential for Stored Cross-Site Scripting attacks.
To fix CVE-2024-5968, update the Photo Gallery by 10Web plugin to version 1.8.28 or later.
CVE-2024-5968 affects installations of the Photo Gallery by 10Web plugin prior to version 1.8.28.
CVE-2024-5968 is classified as a Stored Cross-Site Scripting (XSS) vulnerability.
Yes, high privilege users, such as administrators, can exploit CVE-2024-5968 to perform attacks even when the unfiltered_html capability is disallowed.