The Image Widget WordPress plugin before 4.4.11 does not sanitise and escape some of its Image Widget settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
Metrics
Affected Vendors & Products
References
History
Wed, 14 May 2025 20:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Stellarwp
Stellarwp image Widget |
|
Weaknesses | CWE-79 | |
CPEs | cpe:2.3:a:stellarwp:image_widget:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Stellarwp
Stellarwp image Widget |
Mon, 16 Dec 2024 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
Fri, 13 Dec 2024 06:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Image Widget WordPress plugin before 4.4.11 does not sanitise and escape some of its Image Widget settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
Title | Image Widget < 4.4.11 - Admin+ Stored XSS | |
References |
|

Status: PUBLISHED
Assigner: WPScan
Published: 2024-12-13T06:00:03.573Z
Updated: 2024-12-16T18:59:35.986Z
Reserved: 2024-11-06T19:25:03.608Z
Link: CVE-2024-10939

Updated: 2024-12-16T18:52:44.319Z

Status : Analyzed
Published: 2024-12-13T06:15:25.120
Modified: 2025-05-14T20:17:31.263
Link: CVE-2024-10939

No data.