Vulnerability Description
Unvalidated input and lack of output encoding in the Envira Gallery Lite WordPress plugin, versions before 1.8.3.3, did not properly sanitise the images metadata (namely title) before outputting them in the generated gallery, which could lead to privilege escalation.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Enviragallery | Envira Gallery | < 1.8.3.3 |
Related Weaknesses (CWE)
References
- https://wpscan.com/vulnerability/f3952bd1-ac2f-4007-9e19-6c44a22465f3ExploitThird Party Advisory
- https://wpscan.com/vulnerability/f3952bd1-ac2f-4007-9e19-6c44a22465f3ExploitThird Party Advisory
FAQ
What is CVE-2021-24126?
CVE-2021-24126 is a vulnerability with a CVSS score of 5.4 (MEDIUM). Unvalidated input and lack of output encoding in the Envira Gallery Lite WordPress plugin, versions before 1.8.3.3, did not properly sanitise the images metadata (namely title) before outputting them ...
How severe is CVE-2021-24126?
CVE-2021-24126 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-24126?
Check the references section above for vendor advisories and patch information. Affected products include: Enviragallery Envira Gallery.