VYPR
Unrated severityNVD Advisory· Published Oct 31, 2022· Updated May 7, 2025

Envira Gallery Lite < 1.8.4.7 - Reflected Cross-Site Scripting

CVE-2022-2190

Description

Reflected XSS in Envira Gallery Lite plugin for WordPress before 1.8.4.7 via unsanitized REQUEST_URI output in an attribute.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Reflected XSS in Envira Gallery Lite plugin for WordPress before 1.8.4.7 via unsanitized REQUEST_URI output in an attribute.

Vulnerability

The Envira Gallery Lite plugin for WordPress versions before 1.8.4.7 fails to escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an HTML attribute, as reported in [1]. This allows an attacker to inject arbitrary JavaScript code that executes in the context of the victim's browser when the page is rendered. The vulnerability is present in the plugin's handling of the request URI.

Exploitation

An attacker can craft a malicious URL containing a payload in the request URI. When a user with an old web browser (that does not properly encode characters in attributes) visits the crafted URL, the injected script executes. No authentication is required; the attacker only needs to trick the victim into clicking the link.

Impact

Successful exploitation leads to reflected cross-site scripting (XSS), allowing the attacker to execute arbitrary JavaScript in the victim's browser. This can result in session hijacking, defacement, or redirection to malicious sites. The impact is limited to the victim's browser session and the context of the WordPress site.

Mitigation

The issue is fixed in version 1.8.4.7 of the Envira Gallery Lite plugin. Users should update to this version or later. No workaround is provided. The vulnerability was publicly disclosed on 2022-10-10.

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.