Lazyest Gallery < 1.1.21 - Stored Cross-Site Scripting
mediumCross-site scripting (XSS) vulnerability in the Lazyest Gallery plugin before 1.1.21 for WordPress allows remote attackers to inject arbitrary web script or HTML via an EXIF tag.
- CVSS:
- 6.4
- Affected:
- up to 1.1.21
- Fixed in:
- 1.1.21
- Disclosed:
- Apr 10, 2014