WordPress Google Photos Gallery with Shortcodes Plugin <= 4.0.2 is vulnerable to Cross Site Scripting (XSS)
CVE-2023-51373

7.1HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
29 December 2023

What is CVE-2023-51373?

An improper neutralization of input during web page generation in the Google Photos Gallery with Shortcodes plugin allows for reflected cross-site scripting (XSS) attacks. This vulnerability can be exploited when an attacker sends a specially crafted request that is reflected off a vulnerable web server and executed in the context of the user’s browser. Users of the affected plugin should be aware of the potential for unauthorized actions taken on their behalf, highlighting the need for immediate updates to version 4.0.2 or beyond to mitigate these security risks.

Affected Version(s)

Google Photos Gallery with Shortcodes <= 4.0.2

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Le Ngoc Anh (Patchstack Alliance)
.