Stored Cross-Site Scripting in Picture Gallery Plugin for WordPress
CVE-2024-13584

5.4MEDIUM

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
22 January 2025

Summary

The Picture Gallery – Frontend Image Uploads, AJAX Photo List plugin for WordPress suffers from a Stored Cross-Site Scripting vulnerability due to inadequate input sanitization and output escaping associated with the 'videowhisper_pictures' shortcode. This vulnerability enables authenticated attackers, specifically those with contributor-level access or higher, to inject arbitrary scripts into web pages. These scripts can execute whenever users view the compromised pages, posing significant risks to user data and site integrity.

Affected Version(s)

Picture Gallery – Frontend Image Uploads, AJAX Photo List * <= 1.5.19

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Peter Thaleikis
.