CVE-2024-0604
CVSS 3.1 Score 4.4 of 10 (medium)
Details
Summary
CVE-2024-0604: The FooGallery plugin for WordPress, used in all versions up to 2.4.7, suffers from a Stored Cross-Site Scripting (XSS) vulnerability. This issue stems from insufficient input sanitization and output escaping in the plugin's admin settings. Authenticated attackers, including those with administrator-level permissions, can exploit this flaw to inject arbitrary web scripts. These scripts will execute whenever a user accesses an injected page, posing a significant security risk. This vulnerability impacts only multi-site installations and those where unfiltered_html has been disabled.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.