Vulnerabilities > CVE-2022-2543 - Missing Authorization vulnerability in Visualportfolio Visual Portfolio, Photo Gallery & Post Grid

047910
CVSS 6.1 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
LOW
Integrity impact
LOW
Availability impact
NONE
network
low complexity
visualportfolio
CWE-862

Summary

The Visual Portfolio, Photo Gallery & Post Grid WordPress plugin before 2.18.0 does not have proper authorisation checks in some of its REST endpoints, allowing unauthenticated users to call them and inject arbitrary CSS in arbitrary saved layouts

Vulnerable Configurations

Part Description Count
Application
Visualportfolio
87

Common Weakness Enumeration (CWE)