cleantalk
Vulnerabilities and Security Researches

Gmedia Photo Gallery, CVE-2022-0873

CVE, Research URL

CVE-2022-0873

Application

Gmedia Photo Gallery

Published on
May 16, 2022
Research Description
The Gmedia Photo Gallery WordPress plugin before 1.20.0 does not sanitise and escape the Album's name before outputting it in pages/posts with a media embed, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered-html capability is disallowed
Affected versions
max 1.2.2.
Status
vulnerable