Vulnerability Description
The Visual Portfolio, Photo Gallery & Post Grid WordPress plugin before 2.19.0 does not have proper authorisation checks in some of its REST endpoints, allowing users with a role as low as contributor to call them and inject arbitrary CSS in arbitrary saved layouts
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Visualportfolio | Visual Portfolio\, Photo Gallery \& Post Grid | < 2.19.0 |
Related Weaknesses (CWE)
References
- https://wpscan.com/vulnerability/3ffcee7c-1e03-448c-8006-a9405658cdb7ExploitThird Party Advisory
- https://wpscan.com/vulnerability/3ffcee7c-1e03-448c-8006-a9405658cdb7ExploitThird Party Advisory
FAQ
What is CVE-2022-2597?
CVE-2022-2597 is a vulnerability with a CVSS score of 5.4 (MEDIUM). The Visual Portfolio, Photo Gallery & Post Grid WordPress plugin before 2.19.0 does not have proper authorisation checks in some of its REST endpoints, allowing users with a role as low as contributor...
How severe is CVE-2022-2597?
CVE-2022-2597 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-2597?
Check the references section above for vendor advisories and patch information. Affected products include: Visualportfolio Visual Portfolio\, Photo Gallery \& Post Grid.