Photo Gallery < 1.5.69 - Multiple Reflected Cross-Site Scripting (XSS)
Vulnerability Description
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery WordPress plugin before 1.5.69 was vulnerable to Reflected Cross-Site Scripting (XSS) issues via the gallery_id, tag, album_id and _id GET parameters passed to the bwg_frontend_data AJAX action (available to both unauthenticated and authenticated users)
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-24291
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- ThuraMoeMyint
References
More from Photo Gallery Team
View All →Affected Vendor
Photo Gallery Team
View all reports →