CVE-2023-0764: Gallery by BestWebSoft < 4.7.0 - Author+ Stored Cross-Site Scripting
Published Apr 17, 2023
·Updated
The Gallery by BestWebSoft WordPress plugin before 4.7.0 does not perform proper sanitization of gallery information, leading to a Stored Cross-Site Scription vulnerability. The attacker must have at least the privileges of the Author role.
Affected Software
1 affected component
Bestwebsoft Gallery Wordpress<4.7.0
Event History
Apr 17, 2023
CVE Published
via MITRE·12:17 PM
Data Sourced
via MITRE·12:17 PM
DescriptionWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-0764.
2
What is the severity of CVE-2023-0764?
The severity of CVE-2023-0764 is medium with a CVSS score of 5.4.
3
What is the affected software?
The affected software is The Gallery by BestWebSoft WordPress plugin before version 4.7.0.
4
What is the impact of CVE-2023-0764?
The impact of CVE-2023-0764 is a Stored Cross-Site Scripting vulnerability.
5
How can I fix CVE-2023-0764?
To fix CVE-2023-0764, update The Gallery by BestWebSoft WordPress plugin to version 4.7.0 or later.