The Photoswipe Masonry Gallery WordPress plugin is...
Moderate severity
Unreviewed
Published
Mar 24, 2022
to the GitHub Advisory Database
•
Updated May 5, 2025
Description
Published by the National Vulnerability Database
Mar 23, 2022
Published to the GitHub Advisory Database
Mar 24, 2022
Last updated
May 5, 2025
The Photoswipe Masonry Gallery WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the thumbnail_width, thumbnail_height, max_image_width, and max_image_height parameters found in the ~/photoswipe-masonry.php file which allows authenticated attackers to inject arbitrary web scripts into galleries created by the plugin and on the PhotoSwipe Options page. This affects versions up to and including 1.2.14.
References