cleantalk
Vulnerabilities and Security Researches

Photos and Files Contest Gallery – Contact Form, Upload Form, Social Share and Voting Plugin for WordPress, CVE-2023-5307

CVE, Research URL

CVE-2023-5307

Published on
Oct 31, 2023
Research Description
The Photos and Files Contest Gallery WordPress plugin before 21.2.8.1 does not sanitise and escape some parameters, which could allow unauthenticated users to perform Cross-Site Scripting attacks via certain headers.
Affected versions
Min -, max 21.2.9.
Status
vulnerable