CVE-2024-3899

medium

Description

The Gallery Plugin for WordPress WordPress plugin before 1.8.15 does not sanitise and escape some of its image settings, which could allow users with post-writing privilege such as Author to perform Cross-Site Scripting attacks.

References

https://wpscan.com/vulnerability/e3afadda-4d9a-4a51-b744-10de7d8d8578/

Details

Source: Mitre, NVD

Published: 2024-09-11

Updated: 2024-09-25

Risk Information

CVSS v2

Base Score: 4.7

Vector: CVSS2#AV:N/AC:L/Au:M/C:P/I:P/A:N

Severity: Medium

CVSS v3

Base Score: 4.8

Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

Severity: Medium