WordPress · Gallery Photoblocks · CVE-2026-107323
**Name of the Vulnerable Software and Affected Versions**
Gallery PhotoBlocks versions prior to 1.3.6
**Description**
Insufficient sanitization and escaping of a gallery setting before it is output into an HTML attribute allows users with Contributor-level access and above to perform a Stored Cross-Site Scripting (XSS) attack. This enables the storage of malicious JavaScript that executes in the browser of any user viewing a page containing the gallery, including those with administrator privileges.
**Recommendations**
Update Gallery PhotoBlocks to version 1.3.6 or later.