First published: Thu May 15 2025(Updated: )
The Photo Gallery by 10Web WordPress plugin before 1.8.29 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
10quality Post Gallery | <1.8.29 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-8670 has a high severity rating due to its potential for allowing stored cross-site scripting attacks.
To fix CVE-2024-8670, update the Photo Gallery by 10Web plugin to version 1.8.29 or later.
CVE-2024-8670 affects users of the Photo Gallery by 10Web plugin version prior to 1.8.29, particularly those with high privilege roles.
CVE-2024-8670 is categorized as a stored cross-site scripting (XSS) vulnerability.
Yes, CVE-2024-8670 can be exploited by high privilege users such as admin even when the unfiltered_html capability is restricted.