Photo Gallery by 10Web – Mobile-Friendly Image Gallery, faac0458cd9a2cbf17c4d4476ecea79a7e18905a
- CVE, Research URL
- Published on
- Jul 19, 2021
- Research Description
- Photo Gallery by 10Web – Mobile-Friendly Image Gallery [photo-gallery] < 1.5.79 Photo Gallery by 10Web <= 1.5.78 - Stored Cross-Site Scripting via Uploaded SVG The Photo Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.5.78 due to insufficient sanitization and escaping on SVG uploads. This makes it possible for low-level authenticated attackers, such as authors, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
- Affected versions
-
max 1.5.79.
- Status
-
vulnerable