WordPress Plugin Vulnerabilities
Final Tiles Gallery < 3.4.19 - Authenticated Stored Cross-Site Scripting (XSS)
Description
Multiple cross-site scripting vulnerabilities in Final Tiles Gallery 3.4.18 and lower allow remote attackers to inject arbitrary web script or HTML via the Title and Caption fields of an image. Successful exploitation of this vulnerability would allow an authenticated high-privileged user (author+) to inject arbitrary javascript code into a post using the gallery which is viewed by admin and other users.
Timeline (WPScanTeam):
May 14th, 2020 - Issue confirmed, Vendor Contacted (via https://www.machothemes.com/contact-us-now/) and given 14 days for a response before escalating to WP plugins team.
May 27th, 2020 - v3.4.19 released, fixing the issue.
Proof of Concept
Affects Plugins
References
CVE
Classification
Type
XSS
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
Ngo Van Thien - SunCSR
Submitter
Ngo Van Thien
Submitter twitter
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2020-05-28 (about 5 years ago)
Added
2020-05-28 (about 5 years ago)
Last Updated
2020-06-23 (about 5 years ago)