The Photos and Files Contest Gallery WordPress plugin before 21.3.1 does not sanitize and escape some parameters, which could allow users with a role as low as author to perform Cross-Site Scripting attacks.
Metrics
Affected Vendors & Products
References
History
Tue, 01 Apr 2025 16:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Contest-gallery
Contest-gallery contest Gallery |
|
Weaknesses | CWE-79 | |
CPEs | cpe:2.3:a:contest-gallery:contest_gallery:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Contest-gallery
Contest-gallery contest Gallery |
Sat, 29 Mar 2025 00:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: WPScan
Published: 2024-03-11T17:56:07.447Z
Updated: 2025-03-28T23:22:28.039Z
Reserved: 2024-02-14T03:12:56.965Z
Link: CVE-2024-1487

Updated: 2024-08-01T18:40:21.404Z

Status : Analyzed
Published: 2024-03-11T18:15:18.057
Modified: 2025-04-01T15:44:13.063
Link: CVE-2024-1487

No data.