CVE-2022-41785: WordPress Photo Gallery – Image Gallery by Ape Plugin <= 2.2.8 is vulnerable to Cross Site Scripting (XSS)
Published Mar 21, 2023
·Updated
Auth. (contributor+) Stored Cross-Site Scripting vulnerability in Galleryape Gallery Images Ape plugin <= 2.2.8 versions.
Affected Software
1 affected component
Robogallery Gallery Images Ape Wordpress<=2.2.8
Event History
Mar 21, 2023
CVE Published
via MITRE·05:57 AM
Data Sourced
via MITRE·05:57 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2022-41785?
CVE-2022-41785 is a Stored Cross-Site Scripting vulnerability in the Galleryape Gallery Images Ape plugin <= 2.2.8 versions.
2
How severe is CVE-2022-41785?
CVE-2022-41785 has a severity keyword of 'medium' and a severity value of 5.4.
3
Which software versions are affected by CVE-2022-41785?
Galleryape Gallery Images Ape plugin versions up to and including 2.2.8 are affected by CVE-2022-41785.
4
What is the CWE of CVE-2022-41785?
CVE-2022-41785 is classified under CWE-79, which is the category for Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').
5
How can I fix CVE-2022-41785?
To fix CVE-2022-41785, update the Galleryape Gallery Images Ape plugin to version 2.2.9 or a later version.