cleantalk
Vulnerabilities and Security Researches

Photo Gallery by Ays – Responsive Image Gallery, CVE-2023-2568

CVE, Research URL

CVE-2023-2568

Published on
Jun 12, 2023
Research Description
The Photo Gallery by Ays WordPress plugin before 5.1.7 does not escape some parameters before outputting it back in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin
Affected versions
max 5.1.7.
Status
vulnerable