Medium severity5.4NVD Advisory· Published Jun 22, 2020· Updated Jun 17, 2026
CVE-2020-14962
CVE-2020-14962
Description
Multiple XSS vulnerabilities in the Final Tiles Gallery plugin before 3.4.19 for WordPress allow remote attackers to inject arbitrary web script or HTML via the Title (aka imageTitle) or Caption (aka description) field of an image to wp-admin/admin-ajax.php.
Affected products
3- cpe:2.3:a:machothemes:image_photo_gallery_final_tiles_grid:*:*:*:*:*:wordpress:*:*Range: <3.4.19
- WordPress/Final Tiles Gallery plugindescription
- Range: <3.4.19
Patches
Vulnerability mechanics
References
1- wpvulndb.com/vulnerabilities/10241nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.