« Volver al listado

CVE-2022-2597

Estado: ModificadaMedia (5.4)—

The Visual Portfolio, Photo Gallery & Post Grid WordPress plugin before 2.19.0 does not have proper authorisation checks in some of its REST endpoints, allowing users with a role as low as contributor to call them and inject arbitrary CSS in arbitrary saved layouts

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-2597",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 5.4,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.7,
        "exploitabilityScore": 2.3
      }
    ]
  },
  "affected": [
    {
      "source": "contact@wpscan.com",
      "affectedData": [
        {
          "vendor": "Unknown",
          "product": "Visual Portfolio, Photo Gallery & Post Grid",
          "versions": [
            {
              "status": "affected",
              "version": "2.19.0",
              "lessThan": "2.19.0",
              "versionType": "custom"
            }
          ]
        }
      ]
    }
  ],
  "published": "2022-09-05T13:15:08.430",
  "references": [
    {
      "url": "https://wpscan.com/vulnerability/3ffcee7c-1e03-448c-8006-a9405658cdb7",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "contact@wpscan.com"
    },
    {
      "url": "https://wpscan.com/vulnerability/3ffcee7c-1e03-448c-8006-a9405658cdb7",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "contact@wpscan.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-863"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The Visual Portfolio, Photo Gallery & Post Grid WordPress plugin before 2.19.0 does not have proper authorisation checks in some of its REST endpoints, allowing users with a role as low as contributor to call them and inject arbitrary CSS in arbitrary saved layouts"
    },
    {
      "lang": "es",
      "value": "El plugin Visual Portfolio, Photo Gallery & Post Grid de WordPress versiones anteriores a 2.19.0, no presenta comprobaciones de autorización apropiadas en algunos de sus endpoints REST, lo que permite a usuarios con un rol tan bajo como el de colaborador llamarlos e inyectar CSS arbitrario en diseños guardados arbitrariamente"
    }
  ],
  "lastModified": "2026-06-17T04:42:11.260",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:visualportfolio:visual_portfolio\\,_photo_gallery_\\&_post_grid:*:*:*:*:*:wordpress:*:*",
              "vulnerable": true,
              "matchCriteriaId": "497CEB89-B810-400B-A566-AB30738E3D4A",
              "versionEndExcluding": "2.19.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "contact@wpscan.com"
}