Vulnerability Description
The Gmedia Photo Gallery WordPress plugin before 1.20.0 does not sanitise and escape the Album's name before outputting it in pages/posts with a media embed, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered-html capability is disallowed
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Codeasily | Gmedia Gallery | < 1.20.0 |
Related Weaknesses (CWE)
References
- https://wpscan.com/vulnerability/d5ce4b8a-9aa5-4df8-b521-c2105990a87eExploitThird Party Advisory
- https://wpscan.com/vulnerability/d5ce4b8a-9aa5-4df8-b521-c2105990a87eExploitThird Party Advisory
FAQ
What is CVE-2022-0873?
CVE-2022-0873 is a vulnerability with a CVSS score of 4.8 (MEDIUM). The Gmedia Photo Gallery WordPress plugin before 1.20.0 does not sanitise and escape the Album's name before outputting it in pages/posts with a media embed, which could allow high privilege users suc...
How severe is CVE-2022-0873?
CVE-2022-0873 has been rated MEDIUM with a CVSS base score of 4.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-0873?
Check the references section above for vendor advisories and patch information. Affected products include: Codeasily Gmedia Gallery.