Gallery Plugin for WordPress – Envira Photo Gallery, CVE-2020-9334
- CVE, Research URL
- Published on
- Feb 25, 2020
- Research Description
- A stored XSS vulnerability exists in the Envira Photo Gallery plugin through 1.7.6 for WordPress. Successful exploitation of this vulnerability would allow a authenticated low-privileged user to inject arbitrary JavaScript code that is viewed by other users.
- Affected versions
-
max 1.7.7.
- Status
-
vulnerable