CVE-2024-29810

WordPress Photo Gallery Plugin <= 1.8.21 Reflected Cross Site Scripting in editimage_bwg thumb_url

The thumb_url parameter of the AJAX call to the editimage_bwg action of admin-ajax.php is vulnerable to reflected Cross Site Scripting. The value of the thumb_url parameter is embedded within an existing JavaScript within the response allowing arbitrary JavaScript to be inserted and executed. The attacker must target a an authenticated user with permissions to access this component to exploit this issue.


We have discovered 44,335 live websites that are affected by CVE-2024-29810.

Test my site




Affected Software

Product  Photo Gallery by 10Web
Category Wordpress Plugins
Vulnerable Domains44,335 live websites (42.24% of Photo Gallery by 10Web install base)
Vulnerable Versions
  • from 1.0.1 through 1.8.21
Vulnerable Versions Count329 versions ( 53.50% of all versions)



Details

  • Published - Mar 26, 2024
  • Updated - Aug 2, 2024

Credits

  • AppCheck Ltd. (finder)

CVE-2024-29810 usage by Country

United States11,618 websites



Germany5,520 websites
France2,589 websites
Poland2,345 websites
Russia2,267 websites
GB1,606 websites
Italy1,257 websites
Netherlands1,236 websites
Japan984 websites
Hungary780 websites

CVE-2024-29810 usage by TLD

.com15,881 websites
.de2,904 websites
.org2,288 websites
.ru1,881 websites
.pl1,835 websites
.nl1,154 websites
.co.uk1,034 websites
.it1,012 websites
.net924 websites
.fr880 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-29810

Top websites that are affected by CVE-2024-29810. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*********.kz Kazakhstan**,***
******.name France**,***
**********.**.uk United States**,***
********.cz Czech Republic**,***
***.***.ph Philippines**,***
***.org United States**,***
******************.org United States**,***
****.***.pl Poland***,***
**********.com United States***,***
*****.edu United States***,***
See full domain list

FAQ

A total of 44,335 websites have been identified as vulnerable to CVE-2024-29810, discovered through global website indexing conducted by WebTechSurvey.
Photo Gallery by 10Web is susceptible to CVE-2024-29810 vulnerability.
Photo Gallery by 10Web versions before, and including, 1.8.21 are vulnerable to CVE-2024-29810.