Record summary

CVE-2024-3276 has a selected CVSS score of 6.1 (medium).

Description

The Lightbox & Modal Popup WordPress Plugin WordPress plugin before 2.7.28, foobox-image-lightbox-premium WordPress plugin before 2.7.28 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 1, 2024 · Source: CVE List

Affected products and versions

4
ProductSourceVersion rangeStatus

Lightbox & Modal Popup WordPress Plugin

Default status: unaffected

CVE ListBefore 2.7.28affected

foobox-image-lightbox-premium

Default status: unaffected

CVE ListBefore 2.7.28affected

Default status: unknown

CVE ListBefore 2.7.28affected

Default status: unknown

CVE ListBefore 2.7.28affected

References

2