CVE-2023-25979: WordPress Video Gallery – YouTube Gallery Plugin <= 1.7.6 is vulnerable to Cross Site Scripting (XSS)
Published May 3, 2023
·Updated
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Video Gallery by Total-Soft Video Gallery plugin <= 1.7.6 versions.
Affected Software
1 affected component
Total-Soft Video Gallery Wordpress<1.7.7
Remediation
Information
Update to 1.7.7 or a higher version.
Event History
May 3, 2023
CVE Published
via MITRE·01:37 PM
Data Sourced
via MITRE·01:37 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the CVE ID for this vulnerability?
The CVE ID for this vulnerability is CVE-2023-25979.
2
What is the title of this vulnerability?
The title of this vulnerability is 'Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Video Gallery by Total-Soft Video ...'
3
What is the affected software?
The affected software is Total-Soft Video Gallery plugin version 1.7.6 and below.
4
What is the severity of this vulnerability?
The severity of this vulnerability is medium (4.8).
5
Is there a fix available for this vulnerability?
Yes, there is a fix available. It is recommended to update to version 1.7.7 or above of the Total-Soft Video Gallery plugin.