CVE-2020-14962: XSS
Multiple XSS vulnerabilities in the Final Tiles Gallery plugin before 3.4.19 for WordPress allow remote attackers to inject arbitrary web script or HTML via the Title (aka imageTitle) or Caption (aka description) field of an image to wp-admin/admin-ajax.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-14962?
CVE-2020-14962 is classified as a moderate severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2020-14962?
To fix CVE-2020-14962, upgrade the Final Tiles Gallery plugin to version 3.4.19 or later.
What types of attacks can CVE-2020-14962 facilitate?
CVE-2020-14962 can facilitate cross-site scripting (XSS) attacks, allowing attackers to inject arbitrary web scripts or HTML.
Which versions of the Final Tiles Gallery plugin are affected by CVE-2020-14962?
CVE-2020-14962 affects all versions of the Final Tiles Gallery plugin prior to 3.4.19.
Who is impacted by CVE-2020-14962?
Users of the Final Tiles Gallery plugin on WordPress prior to version 3.4.19 are impacted by CVE-2020-14962.