CVE-2024-13751
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Published Feb 21, 2025
Updated: Feb 25, 2025
CWE ID 79
Summary
CVE-2024-13751 is a stored Cross-Site Scripting (XSS) vulnerability affecting the 3D Photo Gallery plugin for WordPress. This weakness, present in all versions up to 1.3, allows authenticated attackers with Subscriber-level access or higher to inject malicious scripts into pages. The 'des[]' parameter, which is not properly sanitized or output-escaped, is the entry point for these attacks. Successful exploitation results in the execution of the injected scripts whenever a user accesses an affected page.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share