CVE-2024-29833

WordPress Photo Gallery Plugin <= 1.8.21 Stored Cross Site Scripting in UploadHandler

The image upload component allows SVG files and the regular expression used to remove script tags can be bypassed by using a Cross Site Scripting payload which does not match the regular expression; one example of this is the inclusion of whitespace within the script tag. An attacker must target an authenticated user with permissions to access this feature, however once uploaded the payload is also accessible to unauthenticated users.


We have discovered 44,335 live websites that are affected by CVE-2024-29833.

Test my site




Affected Software

Product  Photo Gallery by 10Web
Category Wordpress Plugins
Vulnerable Domains44,335 live websites (42.24% of Photo Gallery by 10Web install base)
Vulnerable Versions
  • from 1.0.1 through 1.8.21
Vulnerable Versions Count329 versions ( 53.50% of all versions)



Details

  • Published - Mar 26, 2024
  • Updated - Aug 2, 2024

Credits

  • AppCheck Ltd. (finder)

CVE-2024-29833 usage by Country

United States11,618 websites



Germany5,520 websites
France2,589 websites
Poland2,345 websites
Russia2,267 websites
GB1,606 websites
Italy1,257 websites
Netherlands1,236 websites
Japan984 websites
Hungary780 websites

CVE-2024-29833 usage by TLD

.com15,881 websites
.de2,904 websites
.org2,288 websites
.ru1,881 websites
.pl1,835 websites
.nl1,154 websites
.co.uk1,034 websites
.it1,012 websites
.net924 websites
.fr880 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-29833

Top websites that are affected by CVE-2024-29833. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*********.kz Kazakhstan**,***
******.name France**,***
**********.**.uk United States**,***
********.cz Czech Republic**,***
***.***.ph Philippines**,***
***.org United States**,***
******************.org United States**,***
****.***.pl Poland***,***
**********.com United States***,***
*****.edu United States***,***
See full domain list

FAQ

A total of 44,335 websites have been identified as vulnerable to CVE-2024-29833, discovered through global website indexing conducted by WebTechSurvey.
Photo Gallery by 10Web is susceptible to CVE-2024-29833 vulnerability.
Photo Gallery by 10Web versions before, and including, 1.8.21 are vulnerable to CVE-2024-29833.