What the vulnerability does
01Description
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in wpdevart Gallery – Image and Video Gallery with Thumbnails plugin <= 2.0.1 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in wpdevart Gallery – Image and Video Gallery with Thumbnails plugin <= 2.0.1 versions.
Explanation of Vulnerability in Simple Terms
The Gallery plugin for WordPress contains a stored cross-site scripting (XSS) vulnerability in versions up to 2.0.1. An attacker can inject malicious scripts through the plugin's input fields, which are then executed in the browsers of site visitors and administrators. This allows theft of session tokens, account hijacking, or malware distribution. The vulnerability requires user interaction—a victim must visit a page containing the injected payload.
What an attacker can do
Inject malicious JavaScript that runs in visitors' browsers, stealing cookies, session tokens, or redirecting users to phishing sites.
Potential impact on your site
Visitors and admins can be compromised; attackers may steal login credentials, inject malware, or deface content.
Conditions required to exploit
No authentication required. A victim must visit a page or admin panel where the attacker's payload is displayed.
Key dates
External resources
Related vulnerabilities