Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Contest Gallery Contest Gallery allows Stored XSS.This issue affects Contest Gallery: from n/a through 24.0.3.
Fixes

Solution

Update the WordPress Contest Gallery plugin to the latest available version (at least 24.0.4).


Workaround

No workaround given by the vendor.

History

Thu, 03 Apr 2025 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Contest-gallery
Contest-gallery contest Gallery
CPEs cpe:2.3:a:contest-gallery:contest_gallery:*:*:*:*:*:wordpress:*:*
Vendors & Products Contest-gallery
Contest-gallery contest Gallery

Thu, 02 Jan 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 02 Jan 2025 12:15:00 +0000

Type Values Removed Values Added
Title WordPress Contest Gallery plugin <= 24.0.3 - Cross Site Scripting (XSS) vulnerability

Thu, 02 Jan 2025 12:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Contest Gallery Contest Gallery allows Stored XSS.This issue affects Contest Gallery: from n/a through 24.0.3.
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2025-01-02T14:52:03.754Z

Reserved: 2024-12-18T19:04:10.960Z

Link: CVE-2024-56237

cve-icon Vulnrichment

Updated: 2025-01-02T14:43:58.652Z

cve-icon NVD

Status : Analyzed

Published: 2025-01-02T12:15:24.993

Modified: 2025-04-03T14:31:20.067

Link: CVE-2024-56237

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.