CVE-2023-28666: XSS
The InPost Gallery WordPress plugin, in versions < 2.2.2, is affected by a reflected cross-site scripting vulnerability in the 'imgurl' parameter to the addinpostgalleryslideitem action, which can only be triggered by an authenticated user.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-28666?
CVE-2023-28666 is a vulnerability in the InPost Gallery WordPress plugin, versions < 2.2.2, that allows for reflected cross-site scripting.
How does CVE-2023-28666 affect the InPost Gallery WordPress plugin?
CVE-2023-28666 affects the InPost Gallery WordPress plugin by allowing an authenticated user to exploit a reflected cross-site scripting vulnerability.
What is the severity of CVE-2023-28666?
CVE-2023-28666 has a severity rating of medium (5.4).
Which version of the InPost Gallery WordPress plugin is affected by CVE-2023-28666?
Versions of the InPost Gallery WordPress plugin prior to 2.2.2 are affected by CVE-2023-28666.
How can I fix CVE-2023-28666?
To fix CVE-2023-28666, update the InPost Gallery WordPress plugin to version 2.2.2 or higher.