Document Gallery < 5.1.1 - Reflected XSS via dg_generate_gallery
33Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 6.1epss 0.2%
exploitation probability
0.2%top 94% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
The Document Gallery WordPress plugin before 5.1.1 does not properly sanitise and escape user input before reflecting it back in the response of an unauthenticated AJAX action, leading to a Reflected Cross-Site Scripting vulnerability which can be exploited against unauthenticated users.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Affected products
Unknown · Document Gallerypublic PoCs found — 1
cve_referencewpscan.com/vulnerability/a3c279ce-5db1-4331-ad74-4eef49619737/unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.