CVE-2022-1946: Gallery < 2.0.0 - Reflected Cross-Site Scripting
Published Jul 4, 2022
·Updated
The Gallery WordPress plugin before 2.0.0 does not sanitise and escape a parameter before outputting it back in the response of an AJAX action (available to both unauthenticated and authenticated users), leading to a Reflected Cross-Site Scripting issue
Affected Software
1 affected component
WpDevArt Gallery Wordpress<2.0.0
Event History
Jul 4, 2022
CVE Published
via MITRE·01:05 PM
Data Sourced
via MITRE·01:05 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for the Gallery WordPress plugin vulnerability?
The vulnerability ID for the Gallery WordPress plugin vulnerability is CVE-2022-1946.
2
What is the severity of CVE-2022-1946?
The severity of CVE-2022-1946 is medium, with a CVSS score of 6.1.
3
Which version of the Gallery WordPress plugin is affected by CVE-2022-1946?
The Gallery WordPress plugin before version 2.0.0 is affected by CVE-2022-1946.
4
What is the impact of CVE-2022-1946?
CVE-2022-1946 can lead to a Reflected Cross-Site Scripting (XSS) issue.
5
Is CVE-2022-1946 exploitable by both unauthenticated and authenticated users?
Yes, CVE-2022-1946 is exploitable by both unauthenticated and authenticated users.