CVE-2022-1394: Photo Gallery < 1.6.4 - Admin+ Stored Cross-Site Scripting
The Photo Gallery by 10Web WordPress plugin before 1.6.4 does not properly validate and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks when unfilteredhtml is disallowed
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-1394?
CVE-2022-1394 is a vulnerability in the Photo Gallery by 10Web WordPress plugin before version 1.6.4 that allows high privilege users to perform Cross-Site Scripting attacks.
How does CVE-2022-1394 affect users?
CVE-2022-1394 affects users of the Photo Gallery by 10Web WordPress plugin before version 1.6.4 and allows high privilege users to perform Cross-Site Scripting attacks.
What is the severity of CVE-2022-1394?
CVE-2022-1394 has a severity rating of 4.8 out of 10, which is considered medium.
How can I fix CVE-2022-1394?
To fix CVE-2022-1394, users should update the Photo Gallery by 10Web WordPress plugin to version 1.6.4 or later.
Where can I find more information about CVE-2022-1394?
More information about CVE-2022-1394 can be found at https://wpscan.com/vulnerability/f7a0df37-3204-4926-84ec-2204a2f22de3.