CVE-2023-2568: Ays-Pro Photo Gallery

Medium severity, CVSS 6.1. EPSS: 0.5% chance of exploitation in the next 30 days.

The Photo Gallery by Ays WordPress plugin before 5.1.7 does not escape some parameters before outputting it back in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin

Affected products

  • Ays-Pro Photo Gallery: before 5.1.7 (fixed in 5.1.7)

Published 2023-06-12. Last modified 2026-06-17.