Lucene search

K
cvelistWPScanCVELIST:CVE-2021-25041
HistoryDec 06, 2021 - 3:55 p.m.

CVE-2021-25041 Photo Gallery by 10Web < 1.5.68 - Reflected Cross-Site Scripting (XSS)

2021-12-0615:55:40
CWE-79
WPScan
www.cve.org
2

0.001 Low

EPSS

Percentile

28.9%

The Photo Gallery by 10Web WordPress plugin before 1.5.68 is vulnerable to Reflected Cross-Site Scripting (XSS) issues via the bwg_album_breadcrumb_0 and shortcode_id GET parameters passed to the bwg_frontend_data AJAX action

CNA Affected

[
  {
    "product": "Photo Gallery by 10Web – Mobile-Friendly Image Gallery",
    "vendor": "Unknown",
    "versions": [
      {
        "lessThan": "1.5.68",
        "status": "affected",
        "version": "1.5.68",
        "versionType": "custom"
      }
    ]
  }
]

0.001 Low

EPSS

Percentile

28.9%

Related for CVELIST:CVE-2021-25041