Description
Cross-site scripting (XSS) vulnerability in admin/plugin.php in Piwigo through 2.8.3 allows remote attackers to inject arbitrary web script or HTML via a crafted filename that is mishandled in a certain error case.
Remediation
References
Related Vulnerabilities
WordPress Plugin HTML5 MP3 Player with Playlist Free Information Disclosure (2.6)
WordPress Plugin MStore API-Create Native Android & iOS Apps On The Cloud Security Bypass (2.1.5)
WordPress Plugin WP Editor.md Cross-Site Scripting (10.0.1)
WordPress Plugin Slimstat Analytics Cross-Site Scripting (4.6.2)