Stored XSS Vulnerability in Envira Photo Gallery Plugin for WordPress
CVE-2020-9334

5.4MEDIUM

Key Information:

Vendor

Wordpress

Vendor
CVE Published:
25 February 2020

What is CVE-2020-9334?

A stored Cross-Site Scripting (XSS) vulnerability has been identified in the Envira Photo Gallery plugin for WordPress, up to version 1.7.6. This vulnerability allows authenticated users with low privileges to inject arbitrary JavaScript code, which could consequently be executed in the browsers of other users who view the affected content. This lack of proper input validation and sanitization poses a significant threat, enabling potential attackers to manipulate website behavior and compromise user security.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.