5.4
CVSSv3

CVE-2022-0750

Published: 23/03/2022 Updated: 07/11/2023
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

The Photoswipe Masonry Gallery WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the thumbnail_width, thumbnail_height, max_image_width, and max_image_height parameters found in the ~/photoswipe-masonry.php file which allows authenticated malicious users to inject arbitrary web scripts into galleries created by the plugin and on the PhotoSwipe Options page. This affects versions up to and including 1.2.14.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

thriveweb photoswipe masonry gallery

Exploits

WordPress Photoswipe Masonry Gallery plugin version 1214 suffers from a persistent cross site scripting vulnerability ...