Beveiligingsadvies

CVE-2022-2597

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2022-09-05 12:35:21
Laatst bijgewerkt 2024-08-03 00:46:03
Toegewezen door WPScan
CVSS-score geen score
Status PUBLISHED

Beschrijving

The Visual Portfolio, Photo Gallery & Post Grid WordPress plugin before 2.19.0 does not have proper authorisation checks in some of its REST endpoints, allowing users with a role as low as contributor to call them and inject arbitrary CSS in arbitrary saved layouts