WordPress Plugin Vulnerabilities

Gallery PhotoBlocks < 1.2.0 - Authenticated Cross-Site Scripting (XSS)

Description

The vulnerability is due to insufficient validation of gallery name parameter and image caption parameter. A remote attacker (any authenticated low privileged user) can exploit this to execute arbitrary script code within the context of the application.

Affects Plugins

References

Classification

Type
XSS
CWE

Miscellaneous

Original Researcher
Vishnupriya Ilango of Fortinet's FortiGuard Labs
Verified
No

Timeline

Publicly Published
2020-07-29 (about 5 years ago)
Added
2020-07-29 (about 5 years ago)
Last Updated
2020-08-06 (about 5 years ago)

Other