CVE-2024-5968

CVSS 3.1 Score 4.8 of 10 (medium)

Details

Published Oct 9, 2024
Updated: Nov 5, 2024
CWE ID 79

Summary

CVE-2024-5968 is a vulnerability affecting the Photo Gallery plugin by 10Web for WordPress. Before version 1.8.28, the plugin fails to adequately sanitize and escape certain Gallery settings. This issue enables high privilege users, including admins, to execute Stored Cross-Site Scripting attacks, bypassing the standard security measure of disallowing the unfiltered_html capability in multisite configurations.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share