First published: Tue Oct 31 2023(Updated: )
The Photos and Files Contest Gallery WordPress plugin before 21.2.8.1 does not sanitise and escape some parameters, which could allow unauthenticated users to perform Cross-Site Scripting attacks via certain headers.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
<21.2.8.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this vulnerability is CVE-2023-5307.
The severity of CVE-2023-5307 is medium.
CVE-2023-5307 affects the Photos and Files Contest Gallery WordPress plugin before version 21.2.8.1.
The CWE ID associated with CVE-2023-5307 is CWE-79.
An unauthenticated user can exploit CVE-2023-5307 by performing Cross-Site Scripting (XSS) attacks via certain headers.