CVE-2022-27853: WordPress Contest Gallery plugin <= 13.1.0.9 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability
Published Apr 18, 2022
·Updated
Authenticated (author or higher role) Stored Cross-Site Scripting (XSS) in Contest Gallery (WordPress plugin) <= 13.1.0.9
Affected Software
1 affected component
contest-gallery Contest Gallery Wordpress<=13.1.0.9
Remediation
Information
Update to 14.0.0 or higher version.
Event History
Apr 18, 2022
CVE Published
via MITRE·04:20 PM
Data Sourced
via MITRE·04:20 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-27853?
The severity of CVE-2022-27853 is medium with a CVSS score of 4.8.
2
How does CVE-2022-27853 affect Contest Gallery?
CVE-2022-27853 affects Contest Gallery plugin version 13.1.0.9 and below.
3
What is the CWE of CVE-2022-27853?
The CWE of CVE-2022-27853 is CWE-79 (Cross-Site Scripting).
4
Is authentication required for CVE-2022-27853 to be exploited?
Yes, authentication as author or higher role is required for CVE-2022-27853 to be exploited.
5
Where can I find more information about CVE-2022-27853?
You can find more information about CVE-2022-27853 at the following references: [Reference 1](https://patchstack.com/database/vulnerability/contest-gallery/wordpress-contest-gallery-plugin-13-1-0-9-authenticated-stored-cross-site-scripting-xss-vulnerability) and [Reference 2](https://wordpress.org/plugins/contest-gallery/)