PT-2024-28158 · WordPress · Wp Photo Album Plus

Stealthcopter

·

Published

2024-07-20

·

Updated

2024-07-22

·

CVE-2024-38713

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions WP Photo Album Plus versions through 8.8.02.002
Description The issue affects the WP Photo Album Plus plugin, allowing for Stored XSS due to improper neutralization of input during web page generation. This enables an attacker to inject malicious scripts into the website.
Recommendations For WP Photo Album Plus versions through 8.8.02.002, update to a version that contains a fix for this issue to prevent exploitation.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-38713

Affected Products

Wp Photo Album Plus