CVE-2024-9416: Modula Image Gallery <= 2.10.1 - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via FancyBox 5 JavaScript Library
The Modula Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's bundled FancyBox JavaScript library (versions <= 5.0.36) due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-9416?
CVE-2024-9416 has a severity rating that indicates a significant risk of Stored Cross-Site Scripting in the affected software.
How do I fix CVE-2024-9416?
To fix CVE-2024-9416, update the Modula Image Gallery plugin to version 2.10.2 or later and ensure the FancyBox library is updated to version 5.0.37 or later.
What software is affected by CVE-2024-9416?
CVE-2024-9416 affects the Modula Image Gallery plugin for WordPress versions up to and including 2.10.1, and the FancyBox JavaScript library versions up to and including 5.0.36.
What kind of attack does CVE-2024-9416 enable?
CVE-2024-9416 enables a Stored Cross-Site Scripting attack, allowing an attacker to inject malicious scripts into webpages viewed by users.
Who is impacted by CVE-2024-9416?
Users of the Modula Image Gallery plugin for WordPress who have not updated to the latest versions are at risk from the vulnerability identified in CVE-2024-9416.