PT-2023-6703 · WordPress · Foogallery
Lourcode
·
Published
2023-04-06
·
Updated
2023-05-25
·
CVE-2023-29439
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
FooGallery plugin versions <= 2.2.35
Description
The issue exists due to insufficient protection of the web page structure in the foogallery image editor modal function of the FooGallery plugin for WordPress. This allows a remote attacker to conduct cross-site scripting attacks. The estimated number of potentially affected devices is not specified.
Recommendations
For FooGallery plugin versions <= 2.2.35, update to a version higher than 2.2.35 to resolve the issue. As a temporary workaround, consider restricting access to the foogallery image editor modal function to minimize the risk of exploitation.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Foogallery