CVE-2024-10545
CVSS 3.1 Score 3.5 of 10 (low)
Details
Published Feb 25, 2025
Summary
CVE-2024-10545 is a vulnerability affecting the Photo Gallery, Sliders, Proofing, and WordPress plugin before version 3.59.9. Despite the unfiltered_html capability being disallowed, especially in multisite setups, this issue fails to sanitize and escape certain Image settings. This oversight can enable high-privilege users, including Admins, to carry out Stored Cross-Site Scripting attacks.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share