CVE-2022-4142

CVE-2022-4142: WordPress Filter Gallery Plugin < 0.1.6 - Admin+ Stored XSS

Vendor Unknown
Product WordPress Filter Gallery Plugin
Published January 2, 2023
Last update April 10, 2025

CVSS base score

What the vulnerability does

01Description

The WordPress Filter Gallery Plugin WordPress plugin before 0.1.6 does not properly escape the filters passed in the ufg_gallery_filters ajax action before outputting them on the page, allowing a high privileged user such as an administrator to inject HTML or javascript to the plugin settings page, even when the unfiltered_html capability is disabled.

Key dates

02Disclosure timeline

January 2, 2023 CVE published
April 10, 2025 Record updated