cleantalk
Vulnerabilities and Security Researches

Gallery Plugin for WordPress – Envira Photo Gallery, CVE-2024-3899

CVE, Research URL

CVE-2024-3899

Published on
Sep 11, 2024
Research Description
The Gallery Plugin for WordPress WordPress plugin before 1.8.15 does not sanitise and escape some of its image settings, which could allow users with post-writing privilege such as Author to perform Cross-Site Scripting attacks.
Affected versions
max 1.8.15.
Status
vulnerable