CVE-2024-5968
CVSS 3.1 Score 4.8 of 10 (medium)
Details
Published Oct 9, 2024
Updated: Nov 5, 2024
CWE ID 79
Summary
CVE-2024-5968 is a vulnerability affecting the Photo Gallery plugin by 10Web for WordPress. Before version 1.8.28, the plugin fails to adequately sanitize and escape certain Gallery settings. This issue enables high privilege users, including admins, to execute Stored Cross-Site Scripting attacks, bypassing the standard security measure of disallowing the unfiltered_html capability in multisite configurations.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.