CVE-2024-5426

Photo Gallery by 10Web – Mobile-Friendly Image Gallery <= 1.8.23 - Authenticated (Contributor+) Stored Cross-Site Scripting via Zipped SVG

The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘svg’ parameter in all versions up to, and including, 1.8.23 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. By default, this can only be exploited by administrators, but the ability to use and configure Photo Gallery can be extended to contributors on pro versions of the plugin.


We have discovered 49,787 live websites that are affected by CVE-2024-5426.

Test my site




Affected Software

Product  Photo Gallery by 10Web
Category Wordpress Plugins
Vulnerable Domains49,787 live websites (47.43% of Photo Gallery by 10Web install base)
Vulnerable Versions
  • from 0 through 1.8.23
Vulnerable Versions Count332 versions ( 53.98% of all versions)



Details

  • Published - Jun 7, 2024
  • Updated - Aug 1, 2024

Credits

  • Tobias Weißhaar (finder)

CVE-2024-5426 usage by Country

United States13,365 websites



Germany6,290 websites
France2,910 websites
Poland2,555 websites
Russia2,370 websites
GB1,827 websites
Netherlands1,411 websites
Italy1,393 websites
Japan1,059 websites
Hungary851 websites

CVE-2024-5426 usage by TLD

.com17,975 websites
.de3,324 websites
.org2,631 websites
.pl1,998 websites
.ru1,965 websites
.nl1,316 websites
.co.uk1,191 websites
.it1,129 websites
.net1,048 websites
.fr975 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-5426

Top websites that are affected by CVE-2024-5426. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*********.kz Kazakhstan**,***
******.name France**,***
************.ru Russia**,***
***********.org United States**,***
**********.**.uk United States**,***
****************.org United States**,***
********.cz Czech Republic**,***
***.***.ph Philippines**,***
***.org United States**,***
******************.org United States**,***
See full domain list

FAQ

A total of 49,787 websites have been identified as vulnerable to CVE-2024-5426, discovered through global website indexing conducted by WebTechSurvey.
Photo Gallery by 10Web is susceptible to CVE-2024-5426 vulnerability.
Photo Gallery by 10Web versions before, and including, 1.8.23 are vulnerable to CVE-2024-5426.