PT-2023-10164 · WordPress · Fancy Gallery Plugin
Published
2023-04-10
·
Updated
2024-05-17
·
CVE-2014-125096
CVSS v2.0
4.0
Medium
| Vector | AV:N/AC:L/Au:S/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Fancy Gallery Plugin version 1.5.12
Description
A vulnerability was found in the Fancy Gallery Plugin on WordPress, affecting an unknown functionality of the file class.options.php of the component Options Page. The manipulation leads to cross site scripting. The attack can be launched remotely. Upgrading to version 1.5.13 is able to address this issue.
Recommendations
For Fancy Gallery Plugin version 1.5.12, upgrade to version 1.5.13 to address the issue. As a temporary workaround, consider restricting access to the
class.options.php file until the upgrade is applied.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fancy Gallery Plugin