3.5
CVSSv2

CVE-2020-14962

Published: 22/06/2020 Updated: 25/06/2020
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

Multiple XSS vulnerabilities in the Final Tiles Gallery plugin prior to 3.4.19 for WordPress allow remote malicious users to inject arbitrary web script or HTML via the Title (aka imageTitle) or Caption (aka description) field of an image to wp-admin/admin-ajax.php.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

machothemes image photo gallery final tiles grid