Stored XSS Vulnerability in Envira Photo Gallery Plugin for WordPress
CVE-2020-9334
5.4MEDIUM
What is CVE-2020-9334?
A stored Cross-Site Scripting (XSS) vulnerability has been identified in the Envira Photo Gallery plugin for WordPress, up to version 1.7.6. This vulnerability allows authenticated users with low privileges to inject arbitrary JavaScript code, which could consequently be executed in the browsers of other users who view the affected content. This lack of proper input validation and sanitization poses a significant threat, enabling potential attackers to manipulate website behavior and compromise user security.