PT-2024-28305 · WordPress · Gallery Plugin

Dmitry Ignatyev

·

Published

2024-09-11

·

Updated

2024-09-25

·

CVE-2024-3899

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions The Gallery Plugin for WordPress versions prior to 1.8.15
Description The issue is related to the lack of sanitization and escaping of some image settings in the plugin, which could allow users with post-writing privileges, such as Authors, to perform Cross-Site Scripting attacks.
Recommendations For versions prior to 1.8.15, update to version 1.8.15 or later to resolve the issue. As a temporary workaround, consider restricting post-writing privileges to trusted users until the update is applied.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-3899

Affected Products

Gallery Plugin