CVE-2024-9776
CVSS 3.1 Score 4.8 of 10 (medium)
Details
Published Oct 12, 2024
Updated: Nov 25, 2024
CWE ID 79
Summary
CVE-2024-9776 is a Stored Cross-Site Scripting vulnerability affecting the ImagePress – Image Gallery plugin for WordPress up to version 1.2.2. This issue arises due to insufficient input sanitization and output escaping in admin settings. Authenticated attackers with administrator-level permissions can exploit this vulnerability to inject arbitrary web scripts that execute when a user accesses an injected page. This threat solely targets multi-site installations and installations where unfiltered_html has been disabled.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.