6.8

CVE-2024-3710

Exploit

Image Photo Gallery Final Tiles Grid < 3.6.0 - Contributor+ Stored XSS

Image Photo Gallery Final Tiles Grid <= 2.5.8 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Image Photo Gallery Final Tiles Grid WordPress plugin before 3.6.0 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admin
Mögliche Gegenmaßnahme
Image Photo Gallery Final Tiles Grid: Update to version 3.6.0, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
WpchillImage Photo Gallery Final Tiles Grid SwPlatformwordpress Version < 3.6.0
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt Image Photo Gallery Final Tiles Grid
Version *-2.5.8
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.47% 0.369
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
134c704f-9b21-4f2e-91b3-4a467353bcc0 6.8 2.1 4.7
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:L
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

https://wpscan.com/vulnerability/bde10913-4f7e-4590-86eb-33bfa904f95f/
Third Party Advisory
Exploit
https://www.wordfence.com/threat-intel/vulnerabilities/id/ae920b3b-6c6f-46c5-b64f-c075a53b4c39
Third Party Advisory