CVE Published: 11/09/2024 |
CVE Updated: 11/09/2024 |
CVE Year: 2024 Source: WPScan |
Vendor: Unknown |
Product: Gallery Plugin for WordPress Status : PUBLISHED
CVE-2024-3899 Description
The Gallery Plugin for WordPress WordPress plugin before 1.8.15 does not sanitise and escape some of its image settings, which could allow users with post-writing privilege such as Author to perform Cross-Site Scripting attacks.