Gallery – Photo Albums Plugin, CVE-2015-7386
- CVE, Research URL
- Home page URL
- Application
- Published on
- Sep 28, 2015
- Research Description
- Multiple cross-site scripting (XSS) vulnerabilities in includes/metaboxes.php in the Gallery - Photo Albums - Portfolio plugin 1.3.47 for WordPress allow remote authenticated users to inject arbitrary web script or HTML via the (1) Media Title or (2) Media Subtitle fields.
- Affected versions
-
Min -, max 1.3.03.
- Status
-
vulnerable
Previous vulnerability researches |
---|
Gallery – Photo Albums Plugin (CVE-2025-31586) , Apr 03, 2025 |
Gallery – Photo Albums Plugin (CVE-2015-7386) , Jun 07, 2024 |