CVE-2024-10875
CVE-2024-10875: WordPress Gallery Manager plugin vulnerable to Cross-Site Scripting (XSS). Unauthenticated attackers can inject arbitrary web scripts.
CVE-2024-10875 is a reflected Cross-Site Scripting (XSS) vulnerability affecting the Gallery Manager plugin for WordPress, versions up to 1.6.58. It arises from the improper use of remove_Query_Arg without adequate escaping. Successful exploitation allows unauthenticated attackers to inject malicious JavaScript into webpages. Users can be tricked into executing this script by clicking a crafted link. Although the CVSS score is 0, the SOCRadar Vulnerability Risk Score (SVRS) of 30 suggests a moderate risk, and the 'In The Wild' tag indicates active exploitation. This vulnerability could lead to account takeover, data theft, or website defacement, emphasizing the need for a prompt update to a patched version.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.