CVE-2024-7818: Misiek Photo Album <= 1.4.3 - Stored XSS via CSRF
The Misiek Photo Album WordPress plugin through 1.4.3 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-7818?
CVE-2024-7818 has been classified as a medium severity vulnerability due to its potential for stored XSS attacks.
How do I fix CVE-2024-7818?
To fix CVE-2024-7818, update the Misiek Photo Album WordPress plugin to version 1.4.4 or later.
Who is affected by CVE-2024-7818?
Users of the Misiek Photo Album WordPress plugin version 1.4.3 and earlier are affected by CVE-2024-7818.
What type of attack can CVE-2024-7818 facilitate?
CVE-2024-7818 can facilitate a Stored Cross-Site Scripting (XSS) attack via a Cross-Site Request Forgery (CSRF) exploit.
What are the implications of CVE-2024-7818 for website administrators?
Website administrators may inadvertently be targeted by attackers to insert malicious scripts that can impact site security and user data.