rt-prettyphoto Plugin rt-prettyphoto.php royal_prettyphoto_plugin_links cross site scripting
CVE-2015-10128
What is CVE-2015-10128?
The rt-prettyphoto plugin for WordPress was found to be vulnerable to a cross-site scripting (XSS) attack, particularly affecting the function royal_prettyphoto_plugin_links within the rt-prettyphoto.php file. This vulnerability allows an attacker to execute arbitrary scripts in the context of a user’s browser session, potentially leading to unauthorized actions or data theft. The issue can be exploited remotely, making affected sites susceptible to manipulation. An upgrade to version 1.3 of the plugin addresses this vulnerability, highlighting the importance of maintaining up-to-date software to ensure security.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
rt-prettyphoto Plugin 1.0
rt-prettyphoto Plugin 1.1
rt-prettyphoto Plugin 1.2
References
CVSS V3.1
CVSS V3.0
Timeline
Vulnerability published
Vulnerability Reserved