WordPress Plugin Vulnerabilities

Final Tiles Gallery < 3.4.19 - Authenticated Stored Cross-Site Scripting (XSS)

Description

Multiple cross-site scripting vulnerabilities in Final Tiles Gallery 3.4.18 and lower allow remote attackers to inject arbitrary web script or HTML via the Title and Caption fields of an image. Successful exploitation of this vulnerability would allow an authenticated high-privileged user (author+) to inject arbitrary javascript code into a post using the gallery which is viewed by admin and other users.

Timeline (WPScanTeam):
May 14th, 2020 - Issue confirmed, Vendor Contacted (via https://www.machothemes.com/contact-us-now/) and given 14 days for a response before escalating to WP plugins team.
May 27th, 2020 - v3.4.19 released, fixing the issue.

Proof of Concept

Affects Plugins

References

Classification

Type
XSS
CWE

Miscellaneous

Original Researcher
Ngo Van Thien - SunCSR
Submitter
Ngo Van Thien
Submitter twitter
Verified
Yes

Timeline

Publicly Published
2020-05-28 (about 5 years ago)
Added
2020-05-28 (about 5 years ago)
Last Updated
2020-06-23 (about 5 years ago)

Other