← WordPress Vulnerabilities
WordPress security by component

Simple Photoswipe

Simple Photoswipe is a WordPress component with 2 published CVE records in this archive. The latest tracked vulnerability was published Jun 28, 2024; the highest CVE/CNA score is 6.5.

Plugin slug: simple-photoswipe

CVE-2024-5570: Simple Photoswipe: A security weakness

Simple Photoswipe is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.

PublishedJun 28, 2024
Safe version guidanceSee mitigation notes
Safe version
Jun 28, 2024 CVE-2024-5570
Simple Photoswipe: A security weakness
Simple Photoswipe is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.5
NVDPending
Jun 26, 2024 CVE-2024-5473
Simple Photoswipe: Cross-site scripting
Simple Photoswipe is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.0
NVDPending