WordPress Gallery Plugin 1.0 - Authenticated Stored Cross-Site Scripting (XSS)



Description
The plugin is vulnerable to a Stored Cross-Site Scripting (XSS) vulnerability in the Image Label Name input.

Affects Plugin

fixed in version 1.2

Classification

Type XSS
OWASP Top 10 A7: Cross-Site Scripting (XSS)
CWE CWE-79

Miscellaneous

Submitter Arash Khazaei
Submitter Twitter 0xClay
Views 5895
Verified No
WPVDB ID 8157

Timeline

Publicly Published 2015-08-17 (over 4 years ago)
Added 2015-08-24 (over 4 years ago)
Last Updated 2015-12-20 (about 4 years ago)

Our Other Services

Online WordPress Vulnerability Scanner WPScan WordPress Security Plugin