WordPress Plugin Vulnerabilities
Photo Gallery by 10web < 1.5.69 - Reflected Cross-Site Scripting (XSS)
Description
The plugin did not properly sanitise the bwg_search_X GET parameter, available in a frontend gallery when the Show Search Box setting is enabled (disabled by default), leading to a reflected Cross-Site Scripting issue
Proof of Concept
Affects Plugins
References
Classification
Type
XSS
OWASP top 10
CWE
CVSS
Miscellaneous
Submitter
WPScanTeam
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2021-02-23 (about 5 years ago)
Added
2021-02-23 (about 5 years ago)
Last Updated
2021-02-23 (about 5 years ago)