CVE-2023-2568: Photo Gallery by Ays < 5.1.7 - Reflected XSS
Published Jun 12, 2023
·Updated
The Photo Gallery by Ays WordPress plugin before 5.1.7 does not escape some parameters before outputting it back in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin
Affected Software
1 affected component
ays-pro Photo Gallery Wordpress<5.1.7
Event History
Jun 12, 2023
CVE Published
via MITRE·05:28 PM
Data Sourced
via MITRE·05:28 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for the Photo Gallery by Ays plugin?
The vulnerability ID for the Photo Gallery by Ays plugin is CVE-2023-2568.
2
What is the severity of CVE-2023-2568?
The severity of CVE-2023-2568 is medium with a severity value of 6.1.
3
What is the affected software for CVE-2023-2568?
The affected software for CVE-2023-2568 is the Photo Gallery by Ays WordPress plugin before version 5.1.7.
4
What is the impact of CVE-2023-2568?
CVE-2023-2568 allows for Reflected Cross-Site Scripting attacks, which could be used against high privilege users such as admin.
5
How can I fix CVE-2023-2568?
To fix CVE-2023-2568, update the Photo Gallery by Ays WordPress plugin to version 5.1.7 or newer.