First published: Tue Dec 06 2022(Updated: )
Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Contest Gallery plugin <= 13.1.0.9 on WordPress.
Credit: audit@patchstack.com audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Contest-gallery Contest Gallery | <=13.1.0.9 | |
<=13.1.0.9 |
Update to 14.0.0 or higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-45848 is medium with a CVSS score of 6.1.
The affected software of CVE-2022-45848 is the Contest Gallery plugin version up to and including 13.1.0.9 on WordPress.
The CWE of CVE-2022-45848 is CWE-79 (Cross-Site Scripting).
To fix CVE-2022-45848, update the Contest Gallery plugin to a version higher than 13.1.0.9.
You can find more information about CVE-2022-45848 at the following reference link: [https://patchstack.com/database/vulnerability/contest-gallery/wordpress-contest-gallery-plugin-13-1-0-9-unauth-stored-cross-site-scripting-xss-vulnerability?_s_id=cve](https://patchstack.com/database/vulnerability/contest-gallery/wordpress-contest-gallery-plugin-13-1-0-9-unauth-stored-cross-site-scripting-xss-vulnerability?_s_id=cve)