CVE-2023-0764: Bestwebsoft Gallery
Medium severity, CVSS 5.4. EPSS: 0.4% chance of exploitation in the next 30 days.
The Gallery by BestWebSoft WordPress plugin before 4.7.0 does not perform proper sanitization of gallery information, leading to a Stored Cross-Site Scription vulnerability. The attacker must have at least the privileges of the Author role.
Affected products
- Bestwebsoft Gallery: before 4.7.0 (fixed in 4.7.0)
Published 2023-04-17. Last modified 2026-06-17.