Vulnerability Description
A stored XSS vulnerability exists in the Envira Photo Gallery plugin through 1.7.6 for WordPress. Successful exploitation of this vulnerability would allow a authenticated low-privileged user to inject arbitrary JavaScript code that is viewed by other users.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Enviragallery | Envira Gallery | <= 1.7.6 |
Related Weaknesses (CWE)
References
- https://wordpress.org/plugins/envira-gallery-lite/#developersRelease NotesThird Party Advisory
- https://wpvulndb.com/vulnerabilities/10089Third Party Advisory
- https://wordpress.org/plugins/envira-gallery-lite/#developersRelease NotesThird Party Advisory
- https://wpvulndb.com/vulnerabilities/10089Third Party Advisory
FAQ
What is CVE-2020-9334?
CVE-2020-9334 is a vulnerability with a CVSS score of 5.4 (MEDIUM). A stored XSS vulnerability exists in the Envira Photo Gallery plugin through 1.7.6 for WordPress. Successful exploitation of this vulnerability would allow a authenticated low-privileged user to injec...
How severe is CVE-2020-9334?
CVE-2020-9334 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-9334?
Check the references section above for vendor advisories and patch information. Affected products include: Enviragallery Envira Gallery.