cleantalk
Vulnerabilities and Security Researches

Image Photo Gallery Final Tiles Grid, CVE-2020-14962

CVE, Research URL

CVE-2020-14962

Published on
Jun 22, 2020
Research Description
Multiple XSS vulnerabilities in the Final Tiles Gallery plugin before 3.4.19 for WordPress allow remote attackers to inject arbitrary web script or HTML via the Title (aka imageTitle) or Caption (aka description) field of an image to wp-admin/admin-ajax.php.
Affected versions
Min -, max 3.3.57.
Status
vulnerable