Record summary

CVE-2019-15829 has a selected CVSS score of 4.8 (medium); EIP currently links 1 Nuclei template.

Description

The photoblocks-grid-gallery plugin before 1.1.33 for WordPress has wp-admin/admin.php?page=photoblocks-edit&id= XSS.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryMEDIUMGallery Photoblocks < 1.1.43 - Cross-Site ScriptingCVSS 4.8

The Gallery PhotoBlocks WordPress plugin was affected by an Authenticated Reflected XSS security vulnerability.

Impact

Authenticated attackers can inject malicious JavaScript through the id parameter, potentially stealing admin session cookies or performing privileged actions on behalf of administrators.

Remediation

Fixed in 1.1.43

WeaknessesCWE-79
Authorsr3Y3r53
Template tagscvecve2019wpwordpresswp-pluginphotoblocks-galleryxssauthenticatedwpscangreentreelabsvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:greentreelabs:gallery_photoblocks:*:*:*:*:*:wordpress:*:*
Shodan: http.html:/wp-content/plugins/photoblocks-grid-gallery/
FOFA: body=/wp-content/plugins/photoblocks-grid-gallery/

Source: ProjectDiscovery

References

3