CVE-2022-37407: WordPress Gallery PhotoBlocks plugin <= 1.2.6 - Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities
Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities in WPChill Gallery PhotoBlocks plugin <= 1.2.6 at WordPress.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-37407?
CVE-2022-37407 is a vulnerability that allows for multiple authenticated stored cross-site scripting (XSS) attacks in WPChill Gallery PhotoBlocks plugin version 1.2.6 and below.
What is the severity of CVE-2022-37407?
CVE-2022-37407 has a severity rating of medium, with a CVSS score of 5.4.
How does CVE-2022-37407 affect WordPress?
CVE-2022-37407 affects WordPress installations using the WPChill Gallery PhotoBlocks plugin version 1.2.6 and below.
How can I fix CVE-2022-37407?
To fix CVE-2022-37407, update the WPChill Gallery PhotoBlocks plugin to a version higher than 1.2.6.
Where can I find more information about CVE-2022-37407?
You can find more information about CVE-2022-37407 at the following references: [1](https://patchstack.com/database/vulnerability/photoblocks-grid-gallery/wordpress-gallery-photoblocks-plugin-1-2-6-multiple-authenticated-stored-cross-site-scripting-xss-vulnerabilities/_s_id=cve) and [2](https://wordpress.org/plugins/photoblocks-grid-gallery/).