CVE-2024-10102
Photo Gallery, Images, Slider in Rbs Image Gallery < 3.2.22 - Contributor+ Stored XSS
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
The Photo Gallery, Images, Slider in Rbs Image Gallery WordPress plugin before 3.2.22 does not sanitise and escape some of its Gallery settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks
Photo Gallery, Images, Slider en Rbs Image Gallery WordPress del complemento de WordPress anterior a la versión 3.2.22 no desinfecta ni evita algunas de las configuraciones de la galería, lo que podría permitir que usuarios con privilegios elevados, como los colaboradores, realicen ataques de cross site scripting almacenado
The Photo Gallery, Images, Slider in Rbs Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Gallery Settings in all versions up to, and including, 3.2.21 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2024-10-17 CVE Reserved
- 2024-12-17 CVE Published
- 2025-01-07 First Exploit
- 2025-01-08 EPSS Updated
- 2025-01-17 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://wpscan.com/vulnerability/3b34d1ec-5370-40a8-964e-663f4f9f42f8 | 2025-01-07 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Unknown Search vendor "Unknown" | Photo Gallery, Images, Slider In Rbs Image Gallery Search vendor "Unknown" for product "Photo Gallery, Images, Slider In Rbs Image Gallery" | < 3.2.22 Search vendor "Unknown" for product "Photo Gallery, Images, Slider In Rbs Image Gallery" and version " < 3.2.22" | en |
Affected
|