CVE-2022-27853Cross-site Scripting in Gallery

Severity
4.8MEDIUMNVD
EPSS
0.2%
top 54.85%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 18
Latest updateSep 27

Description

Authenticated (author or higher role) Stored Cross-Site Scripting (XSS) in Contest Gallery (WordPress plugin) <= 13.1.0.9

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:NExploitability: 1.7 | Impact: 2.7

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-hqfw-qph2-8f38: Authenticated (author or higher role) Stored Cross-Site Scripting (XSS) in Contest Gallery (WordPress plugin) <= 132022-04-19
CVEList
WordPress Contest Gallery plugin <= 13.1.0.9 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability2022-04-18

📋Vendor Advisories

1
Cisco
Vulnerabilities in Layer 2 Network Security Controls Affecting Cisco Products: September 20222022-09-27
CVE-2022-27853 — Cross-site Scripting in Gallery | cvebase