The thumb_url parameter of the AJAX call to the editimage_bwg action of admin-ajax.php is vulnerable to reflected Cross Site Scripting. The value of the thumb_url parameter is embedded within an existing JavaScript within the response allowing arbitrary JavaScript to be inserted and executed. The attacker must target a an authenticated user with permissions to access this component to exploit this issue.
We have discovered 44,335 live websites that are affected by CVE-2024-29810.
Product | |
Category | Wordpress Plugins |
Vulnerable Domains | 44,335 live websites (42.24% of Photo Gallery by 10Web install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 329 versions ( 53.50% of all versions) |
![]() | 11,618 websites |
![]() | 5,520 websites |
![]() | 2,589 websites |
![]() | 2,345 websites |
![]() | 2,267 websites |
![]() | 1,606 websites |
![]() | 1,257 websites |
![]() | 1,236 websites |
![]() | 984 websites |
![]() | 780 websites |
.com | 15,881 websites |
.de | 2,904 websites |
.org | 2,288 websites |
.ru | 1,881 websites |
.pl | 1,835 websites |
.nl | 1,154 websites |
.co.uk | 1,034 websites |
.it | 1,012 websites |
.net | 924 websites |
.fr | 880 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
*********.kz | ![]() | **,*** | |
******.name | ![]() | **,*** | |
**********.**.uk | ![]() | **,*** | |
********.cz | ![]() | **,*** | |
***.***.ph | ![]() | **,*** | |
***.org | ![]() | **,*** | |
******************.org | ![]() | **,*** | |
****.***.pl | ![]() | ***,*** | |
**********.com | ![]() | ***,*** | |
*****.edu | ![]() | ***,*** |
FAQ