Description
A stored cross-site scripting (XSS) vulnerability in the Configuration page of Piwigo v14.5.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Page banner parameter.
Remediation
References
Related Vulnerabilities
WordPress Plugin Software License Manager Cross-Site Request Forgery (4.4.5)
WordPress Plugin Stylish Price List Security Bypass (6.8.14)
WordPress Plugin WP Accessibility Cross-Site Scripting (1.6.10)
WordPress Plugin WP Safe Search 'v1' Parameter Cross-Site Scripting (0.7)
WordPress Plugin WP Job Manager Cross-Site Scripting (1.26.1)