PT-2022-25413 · 10Web · The Photo Gallery

Kazet1234

+1

·

Published

2022-12-19

·

Updated

2022-12-22

·

CVE-2022-4058

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions The Photo Gallery by 10Web WordPress plugin versions prior to 1.8.3
Description The issue arises from the plugin's failure to validate and escape certain parameters before outputting them in JS code on another page. This could lead to a Stored XSS issue when an attacker tricks a logged-in admin into opening a malicious URL or page.
Recommendations For versions prior to 1.8.3, update to version 1.8.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the plugin's functionality for logged-in admins until the update is applied.

Exploit

Fix

Related Identifiers

CVE-2022-4058

Affected Products

The Photo Gallery