CVE-2022-0750
Photoswipe Masonry Gallery <= 1.2.14 Stored Cross-Site Scripting
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
The Photoswipe Masonry Gallery WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the thumbnail_width, thumbnail_height, max_image_width, and max_image_height parameters found in the ~/photoswipe-masonry.php file which allows authenticated attackers to inject arbitrary web scripts into galleries created by the plugin and on the PhotoSwipe Options page. This affects versions up to and including 1.2.14.
El plugin Photoswipe Masonry Gallery de WordPress es vulnerable a un ataque de tipo Cross-Site Scripting debido a una insuficiencia de escape y saneo de los parámetros thumbnail_width, thumbnail_height, max_image_width y max_image_height que se encuentran en el archivo ~/photoswipe-masonry.php, lo que permite a atacantes autenticados inyectar scripts web arbitrarios en las galerías creadas por el plugin y en la página PhotoSwipe Options. Esto afecta a las versiones hasta 1.2.14 incluyéndola
WordPress Photoswipe Masonry Gallery plugin version 1.2.14 suffers from a persistent cross site scripting vulnerability.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2022-02-24 CVE Reserved
- 2022-02-24 CVE Published
- 2022-02-25 First Exploit
- 2025-04-23 EPSS Updated
- 2025-05-05 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
https://wordpress.org/plugins/photoswipe-masonry | Product | |
https://www.wordfence.com/threat-intel/vulnerabilities/id/64624d4c-3ffb-4516-a938-0accde24c79f?source=cve | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Thriveweb Search vendor "Thriveweb" | Photoswipe Masonry Gallery Search vendor "Thriveweb" for product "Photoswipe Masonry Gallery" | < 1.2.15 Search vendor "Thriveweb" for product "Photoswipe Masonry Gallery" and version " < 1.2.15" | wordpress |
Affected
|