CVE-2023-2708: Video Gallery <= 1.0.10 - Reflected Cross-Site Scripting
The Video Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘searchterm’ parameter in versions up to, and including, 1.0.10 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-2708?
CVE-2023-2708 is a vulnerability in the Video Gallery plugin for WordPress that allows unauthenticated attackers to inject arbitrary web scripts.
How does CVE-2023-2708 impact WordPress?
CVE-2023-2708 allows unauthenticated attackers to perform reflected cross-site scripting attacks on WordPress sites using the Video Gallery plugin.
What is the severity of CVE-2023-2708?
CVE-2023-2708 has a severity score of 6.1, which is considered medium.
How can I fix CVE-2023-2708?
To fix CVE-2023-2708, update the Video Gallery plugin to version 1.0.11 or later.
Where can I find more information about CVE-2023-2708?
You can find more information about CVE-2023-2708 in the references provided: [LINK1], [LINK2], [LINK3].