Stored Cross-Site Scripting in Picture Gallery Plugin for WordPress
CVE-2024-13584
5.4MEDIUM
Key Information:
- Vendor
- Wordpress
- Vendor
- CVE Published:
- 22 January 2025
Summary
The Picture Gallery – Frontend Image Uploads, AJAX Photo List plugin for WordPress suffers from a Stored Cross-Site Scripting vulnerability due to inadequate input sanitization and output escaping associated with the 'videowhisper_pictures' shortcode. This vulnerability enables authenticated attackers, specifically those with contributor-level access or higher, to inject arbitrary scripts into web pages. These scripts can execute whenever users view the compromised pages, posing significant risks to user data and site integrity.
Affected Version(s)
Picture Gallery – Frontend Image Uploads, AJAX Photo List * <= 1.5.19
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Peter Thaleikis