WordPress Photo Gallery by Ays Plugin <= 5.1.3 is vulnerable to Cross Site Scripting (XSS)
CVE-2023-32107
7.1HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 18 August 2023
What is CVE-2023-32107?
The Photo Gallery Team plugin, specifically version 5.1.3 and earlier, is susceptible to an unauthenticated reflected Cross-Site Scripting vulnerability. This flaw allows an attacker to inject malicious scripts into web pages, potentially exposing users to harmful actions. Since the vulnerability occurs without authentication, it poses significant risks, making it crucial for users to update to a secure version promptly. For further protection, website administrators are advised to implement security measures to mitigate the risks associated with this type of vulnerability.
Affected Version(s)
Photo Gallery by Ays β Responsive Image Gallery <= 5.1.3