Envira Gallery Lite < 1.8.3.3 - Authenticated Stored Cross-Site Scripting
Vulnerability Description
Unvalidated input and lack of output encoding in the Envira Gallery Lite WordPress plugin, versions before 1.8.3.3, did not properly sanitise the images metadata (namely title) before outputting them in the generated gallery, which could lead to privilege escalation.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-24126
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- minhtuanact
More from Unknown
View All →Affected Vendor
Unknown
View all reports →