Cross-site Scripting (XSS) Vulnerability in Photo Gallery by 10Web
CVE-2024-32583

7.1HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
18 April 2024

What is CVE-2024-32583?

A Cross-site Scripting (XSS) vulnerability has been identified in the Photo Gallery plugin by 10Web, which allows attackers to inject malicious scripts into web pages displayed to users. This vulnerability affects versions of Photo Gallery from n/a through 1.8.21, leading to the potential for reflected XSS attacks. Users of affected versions are encouraged to update their plugins to protect against unauthorized script execution and safeguard their websites from exploitation.

Affected Version(s)

Photo Gallery by 10Web <= 1.8.21

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

.