First published: Wed Mar 22 2023(Updated: )
The InPost Gallery WordPress plugin, in versions < 2.2.2, is affected by a reflected cross-site scripting vulnerability in the 'imgurl' parameter to the add_inpost_gallery_slide_item action, which can only be triggered by an authenticated user.
Credit: vulnreport@tenable.com
Affected Software | Affected Version | How to fix |
---|---|---|
Pluginus Inpost Gallery | <=2.1.4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-28666 is a vulnerability in the InPost Gallery WordPress plugin, versions < 2.2.2, that allows for reflected cross-site scripting.
CVE-2023-28666 affects the InPost Gallery WordPress plugin by allowing an authenticated user to exploit a reflected cross-site scripting vulnerability.
CVE-2023-28666 has a severity rating of medium (5.4).
Versions of the InPost Gallery WordPress plugin prior to 2.2.2 are affected by CVE-2023-28666.
To fix CVE-2023-28666, update the InPost Gallery WordPress plugin to version 2.2.2 or higher.