PT-2020-7802 · WordPress · Wordpress Photo Gallery

Sven Schleier

·

Published

2020-02-08

·

Updated

2020-02-11

·

CVE-2015-1394

CVSS v2.0

3.5

Low

VectorAV:N/AC:M/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions: WordPress Photo Gallery plugin versions prior to 1.2.11
Description: The issue allows remote authenticated users to inject arbitrary web script or HTML via certain parameters in an addImages action to the "wp-admin/admin-ajax.php" API endpoint. The vulnerable parameters include sort by, sort order, items view, dir, clipboard task, clipboard files, clipboard src, and clipboard dest.
Recommendations: For WordPress Photo Gallery plugin versions prior to 1.2.11, update to version 1.2.11 or later to resolve the issue. As a temporary workaround, consider restricting access to the "wp-admin/admin-ajax.php" API endpoint for untrusted users until the update is applied. Avoid using the vulnerable parameters in the addImages action until the issue is resolved.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-1394

Affected Products

Wordpress Photo Gallery