MaxGalleria <= 6.4.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via maxgallery_thumb Shortcode
medium
The MaxGalleria plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's maxgallery_thumb shortcode in all versions up to, and including, 6.4.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contr...
- CVSS:
- 6.4
- Affected:
- up to 6.4.4
- Fixed in:
- 6.4.5
- Disclosed:
- Jun 18, 2024
CVE-2024-5970 on NVD →
MaxGalleria [maxgalleria] < 6.4.5
unknown
[en] The MaxGalleria plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's maxgallery_thumb shortcode in all versions up to, and including, 6.4.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with...
- Affected:
- up to 6.4.5
- Fixed in:
- 6.4.5
- Disclosed:
- Jun 18, 2024
CVE-2024-5970 on NVD →
MaxGalleria [maxgalleria] < 6.4.3
unknown
[en] The MaxGalleria plugin for WordPress is vulnerable to unauthorized image upload due to a missing capability check on the add_media_library_images_to_gallery function in all versions up to, and including, 6.4.2. This makes it possible for authenticated attackers, with subscriber access or above, to upload arbitrary...
- Affected:
- up to 6.4.3
- Fixed in:
- 6.4.3
- Disclosed:
- May 2, 2024
CVE-2024-3581 on NVD →
MaxGalleria <= 6.4.2 - Missing Authorization
medium
The MaxGalleria plugin for WordPress is vulnerable to unauthorized image upload due to a missing capability check on the add_media_library_images_to_gallery function in all versions up to, and including, 6.4.2. This makes it possible for authenticated attackers, with subscriber access or above, to upload arbitrary imag...
- CVSS:
- 4.3
- Affected:
- up to 6.4.2
- Fixed in:
- 6.4.3
- Disclosed:
- Apr 19, 2024
CVE-2024-3581 on NVD →
MaxGalleria [maxgalleria] < 6.2.8
unknown
[en] Authenticated (author or higher user role) Stored Cross-Site Scripting (XSS) vulnerability discovered in MaxGalleria WordPress plugin (versions 6.2.5).
- Affected:
- up to 6.2.8
- Fixed in:
- 6.2.8
- Disclosed:
- Mar 18, 2022
CVE-2022-25603 on NVD →
MaxGalleria <= 6.2.5 - Stored Cross-Site Scripting
medium
Authenticated (author or higher user role) Stored Cross-Site Scripting (XSS) vulnerability discovered in MaxGalleria WordPress plugin (versions 6.2.5).
- CVSS:
- 4.8
- Affected:
- up to 6.2.7
- Fixed in:
- 6.2.7
- Disclosed:
- Feb 22, 2022
CVE-2022-25603 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database