CVE-2020-14962
Summary
| CVE | CVE-2020-14962 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-06-22 00:15:00 UTC |
| Updated | 2020-06-25 20:10:00 UTC |
| Description | Multiple XSS vulnerabilities in the Final Tiles Gallery plugin before 3.4.19 for WordPress allow remote attackers to inject arbitrary web script or HTML via the Title (aka imageTitle) or Caption (aka description) field of an image to wp-admin/admin-ajax.php. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Machothemes | Image Photo Gallery Final Tiles Grid | All | All | All | All |
| Application | Machothemes | Image Photo Gallery Final Tiles Grid | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Final Tiles Gallery < 3.4.19 - Authenticated Stored Cross-Site Scripting (XSS) Security Vulnerability | MISC | wpvulndb.com | Exploit, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.