CVE-2023-29439
HIGH NUCLEIFooPlugins FooGallery <= 2.2.35 - Unauthenticated Reflected Cross-Site Scripting
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2023-29439. PoCs published by LOURC0D3. A Nuclei detection template is also available.
AI-analyzed exploit summary This repository describes a reflected XSS vulnerability in the WordPress Foogallery plugin (versions 2.2.35 and earlier). The vulnerability arises from improper sanitization in the `foogallery_image_editor_modal` function, allowing unauthenticated attackers to inject malicious scripts via a crafted URL parameter.
Description
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in FooPlugins FooGallery plugin <= 2.2.35 versions.
Exploits (1)
This repository describes a reflected XSS vulnerability in the WordPress Foogallery plugin (versions 2.2.35 and earlier). The vulnerability arises from improper sanitization in the `foogallery_image_editor_modal` function, allowing unauthenticated attackers to inject malicious scripts via a crafted URL parameter.
Nuclei Templates (1)
http.html:/wp-content/plugins/foogallery/
body=/wp-content/plugins/foogallery/
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L