vendor:
Filterable Portfolio Gallery
by:
Murat DEMIRCI
9.8
CVSS
CRITICAL
Stored Cross-Site Scripting (XSS)
79
CWE
Product Name: Filterable Portfolio Gallery
Affected Version From: 1
Affected Version To: 1
Patch Exists: YES
Related CWE:
CPE: a:filterable-portfolio:filterable_portfolio_gallery:1.0
Platforms Tested: Windows 10
2021
WordPress Plugin Filterable Portfolio Gallery 1.0 – ‘title’ Stored Cross-Site Scripting (XSS)
A stored Cross-Site Scripting (XSS) vulnerability exists in WordPress Plugin Filterable Portfolio Gallery 1.0, which allows an attacker to inject malicious JavaScript code into the 'title' field. An attacker can exploit this vulnerability by entering a malicious JavaScript payload into the 'title' field, saving and previewing it. The payload will be stored in the database and will be executed when the page is viewed.
Mitigation:
The vendor has released an update to address this vulnerability. Users should update to the latest version of the plugin.