vendor:
Picture Gallery
by:
Aryan Chehreghani
8.3
CVSS
HIGH
Stored Cross-Site Scripting (XSS)
79
CWE
Product Name: Picture Gallery
Affected Version From: 1.4.2002
Affected Version To: 1.4.2002
Patch Exists: NO
Related CWE:
CPE: a:picture_gallery:picture_gallery:1.4.2
Platforms Tested: Windows 10
2021
WordPress Plugin Picture Gallery 1.4.2 – ‘Edit Content URL’ Stored Cross-Site Scripting (XSS)
The WordPress Plugin Picture Gallery 1.4.2 is vulnerable to stored cross-site scripting (XSS) attacks. An attacker can exploit this vulnerability by injecting malicious JavaScript code into the 'Edit Content URL' input field in the admin panel. When the code is triggered, it executes in the context of the affected website, allowing the attacker to steal sensitive information or perform unauthorized actions on behalf of the user.
Mitigation:
To mitigate this vulnerability, users are advised to update to the latest version of the Picture Gallery plugin. Additionally, input validation and output encoding should be implemented to prevent XSS attacks.