CVE-2024-3710: medium-severity vulnerability in Image Photo Gallery Final Tiles Grid
Image Photo Gallery Final Tiles Grid < 3.6.0 - Contributor+ Stored XSS
Published · Updated
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 6.8epss 0.5%
exploitation probability
0.5%top 61% of all CVEs
observed exploitation
nono source reports it
The Image Photo Gallery Final Tiles Grid WordPress plugin before 3.6.0 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admin
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:L
Affected products
Unknown · Image Photo Gallery Final Tiles GridRelated CVEs — Image Photo Gallery Final Tiles Grid
In the same product, most dangerous first.
CVE-2022-0186—Image Photo Gallery Final Tiles Grid < 3.5.3 - Contributor+ Stored Cross-Site ScriptingEPSS 0.6%CVE-2026-104646MEDIUMImage Photo Gallery Final Tiles Grid < 3.6.14 - Contributor+ Stored XSS via Gallery Shortcode AttributesEPSS —CVE-2026-104645LOWImage Photo Gallery Final Tiles Grid < 3.6.14 - Contributor+ Arbitrary Gallery Cloning, Image Modification and Post Meta Update via IDOREPSS —