1 results (0.001 seconds)

CVSS: 6.5EPSS: 0%CPEs: 1EXPL: 0

25 Mar 2025 — Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GhozyLab Gallery for Social Photo allows Stored XSS.This issue affects Gallery for Social Photo: from n/a through 1.0.0.35. The Gallery for Social Photo plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.0.0.36 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access an... • https://patchstack.com/database/wordpress/plugin/feed-instagram-lite/vulnerability/wordpress-gallery-for-social-photo-plugin-1-0-0-35-cross-site-scripting-xss-vulnerability?_s_id=cve • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •