vendor:
FooGallery
by:
Unk9vvN
5.5
CVSS
MEDIUM
Persistent Cross-Site Scripting
79
CWE
Product Name: FooGallery
Affected Version From: 1.8.12
Affected Version To: 1.8.12
Patch Exists: NO
Related CWE:
CPE: a:wordpress:foogallery:1.8.12
Platforms Tested: Kali Linux
2019
WordPress FooGallery 1.8.12 – Persistent Cross-Site Scripting
This vulnerability is in the validation mode and is located in the plugin settings panel. The vulnerability type is stored and it happens because in the settings there is a select tag with options. By breaking the option and writing a script tag, an attacker can execute arbitrary code.
Mitigation:
Update to the latest version of the plugin.