Record summary

CVE-2022-0873 has a selected CVSS score of 4.8 (medium); EIP currently links 1 Nuclei template.

Description

The Gmedia Photo Gallery WordPress plugin before 1.20.0 does not sanitise and escape the Album's name before outputting it in pages/posts with a media embed, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered-html capability is disallowed

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus

Gmedia Photo Gallery

CVE List1.20.0 to < 1.20.0affected

Nuclei templates

1
ProjectDiscoveryMEDIUMWordPress Gmedia Photo Gallery Plugin < 1.20.0 - Cross-Site ScriptingCVSS 4.8

The Gmedia Photo Gallery WordPress plugin before 1.20.0 does not sanitise and escape the album's name before outputting it in pages or posts with a media embed, which could allow high privilege users such as admin to perform Cross-Site Scripting (XSS) attacks even when the unfiltered-html capability is disallowed. (CVE-2022-0873)

Impact

Successful exploitation could allow an attacker with high privileges, such as admin, to inject arbitrary JavaScript or HTML in the context of other users who view affected posts and pages, potentially leading to session hijacking, defacement, or other malicious actions.

Remediation

Update the Gmedia Photo Gallery plugin to version 1.20.0 or later to mitigate this vulnerability.

WeaknessesCWE-79
Authorsritikchaddha
Template tagscvecve2022wpwordpresswp-plugingmediaxssauthenticated
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:codeasily:gmedia_gallery:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

2