First published: Tue May 16 2023(Updated: )
The Video Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘search_term’ parameter in versions up to, and including, 1.0.10 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
I13websolution Video Gallery | <1.0.11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-2708 is a vulnerability in the Video Gallery plugin for WordPress that allows unauthenticated attackers to inject arbitrary web scripts.
CVE-2023-2708 allows unauthenticated attackers to perform reflected cross-site scripting attacks on WordPress sites using the Video Gallery plugin.
CVE-2023-2708 has a severity score of 6.1, which is considered medium.
To fix CVE-2023-2708, update the Video Gallery plugin to version 1.0.11 or later.
You can find more information about CVE-2023-2708 in the references provided: [LINK1], [LINK2], [LINK3].