← back
CVE-2021-24515

Video Gallery - Vimeo and YouTube Gallery < 1.1.5 - Admin+ Stored Cross-Site Scripting

EPSS 0.6%CWE-79
The Video Gallery WordPress plugin before 1.1.5 does not escape the Title and Description of the videos in a gallery before outputting them in attributes, leading to Stored Cross-Site Scripting issues

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →