Multiple XSS vulnerabilities in the Final Tiles Gallery plugin before 3.4.19 for WordPress allow remote attackers to inject arbitrary web script or HTML via the Title (aka imageTitle) or Caption (aka description) field of an image to wp-admin/admin-ajax.php.
References
Link Resource
https://wpvulndb.com/vulnerabilities/10241 Exploit Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2020-06-21T23:04:15

Updated: 2020-06-21T23:04:15

Reserved: 2020-06-21T00:00:00


Link: CVE-2020-14962

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2020-06-22T00:15:10.303

Modified: 2020-06-25T20:10:17.450


Link: CVE-2020-14962

JSON object: View

cve-icon Redhat Information

No data.

CWE