Photoswipe Masonry Gallery <= 1.2.14 Stored Cross-Site Scripting
mediumThe Photoswipe Masonry Gallery WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the thumbnail_width, thumbnail_height, max_image_width, and max_image_height parameters found in the ~/photoswipe-masonry.php file which allows authenticated attackers to inject arbitr...
- CVSS:
- 6.4
- Affected:
- up to 1.2.14
- Fixed in:
- 1.2.15
- Disclosed:
- Feb 24, 2022