CVE Database /
CVE-2024-2840
CVE · Medium
CVE-2024-2840 — Enhanced Media Library [enhanced-media-library] < 2.8.10
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-2840
|
Enhanced Media Library [enhanced-media-library] < 2.8.10 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
5.4
|
< 2.8.10
|
2.8.10 |
2024-04-15 |
—
|
CVE-2024-2840
The Enhanced Media Library plugin contains a stored cross-site scripting vulnerability affecting versions 2.8.9 and earlier, stemming from the plugin's permission of dfxp file uploads without proper sanitization. Attackers with author-level privileges or higher can upload malicious files containing arbitrary JavaScript code that will execute in the browsers of users viewing affected pages. This flaw requires authentication to exploit but allows attackers to inject persistent malicious scripts into WordPress media galleries.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings