PT-2023-25083 · WordPress · Rbs Image Gallery

Felipe Restrepo Rodriguez

·

Published

2023-09-04

·

Updated

2023-09-08

·

CVE-2023-3499

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Rbs Image Gallery WordPress plugin versions prior to 3.2.16
Description The issue concerns the Rbs Image Gallery WordPress plugin, where certain settings are not properly sanitized and escaped. This could allow high-privilege users, such as administrators, to perform Stored Cross-Site Scripting attacks. This issue is notable even in setups where the unfiltered html capability is disallowed, such as in multisite configurations.
Recommendations For versions prior to 3.2.16, update to version 3.2.16 or later to resolve the issue.

Exploit

Fix

Related Identifiers

CVE-2023-3499

Affected Products

Rbs Image Gallery