Lucene search

K
wpvulndbWpvulndbWPVDB-ID:0531B3DD-46C0-477F-B45A-207F39A5B3E5
HistoryJun 15, 2023 - 12:00 a.m.

NextGen GalleryView <= 0.5.5 - Reflected XSS

2023-06-1500:00:00
wpscan.com
3
plugin vulnerability
xss
parameter sanitisation

0.001 Low

EPSS

Percentile

19.9%

The plugin does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CPENameOperatorVersion
wordpress-nextgen-galleryvieweq*

0.001 Low

EPSS

Percentile

19.9%

Related for WPVDB-ID:0531B3DD-46C0-477F-B45A-207F39A5B3E5