cleantalk
Vulnerabilities and Security Researches

Gallery Plugin for WordPress – Envira Photo Gallery, CVE-2020-9334

CVE, Research URL

CVE-2020-9334

Published on
Feb 25, 2020
Research Description
A stored XSS vulnerability exists in the Envira Photo Gallery plugin through 1.7.6 for WordPress. Successful exploitation of this vulnerability would allow a authenticated low-privileged user to inject arbitrary JavaScript code that is viewed by other users.
Affected versions
max 1.7.7.
Status
vulnerable