CVE-2021-24529
The Grid Gallery β Photo Image Grid Gallery WordPress plugin before 1.2.5 does not properly sanitize the title field for image galleries when adding them via the admin dashboard, resulting in an authenticated Stored Cross-Site Scripting vulnerability.
- Affected products
- The Grid Gallery
- Awplife Grid Gallery
- < 1.2.5
- Fix
- Available
- CVSS 3.1
- 5.4 MEDIUM
- EPSS
- 0.6% (48th percentile)
- Weakness
- CWE-79
- NVD status
- Modified
- Published
- 2021-08-23
CVE-2021-24529 at NVD
1 known exploit for CVE-2021-24529
Proof-of-concept code and exploit modules indexed by Sploitus