CVE-2023-5307 Information
Nov 02, 2023
cve
Description
The Photos and Files Contest Gallery WordPress plugin before 21.2.8.1 does not sanitise and escape some parameters which could allow unauthenticated users to perform Cross-Site Scripting attacks via certain headers.
Reference
https://research.cleantalk.org/cve-2023-5307-photos-and-files-contest-gallery-contact-form-21-2-8-1-unauthenticated-stored-xss-via-http-headers https://wpscan.com/vulnerability/6fac1e09-21ab-430d-b56d-195e7238c08c
Share on: