WordPress · Video Gallery For Woocommerce · CVE-2026-10104
**Name of the Vulnerable Software and Affected Versions**
Product Video Gallery for Woocommerce versions prior to 1.5.1.9
**Description**
Stored Cross-Site Scripting occurs due to insufficient input sanitization and output escaping. Authenticated attackers with shop manager-level access or higher can inject arbitrary web scripts via the `custom thumbnail` parameter. These scripts execute whenever a user accesses the affected pages, including public product pages.
**Recommendations**
Update to version 1.5.1.9.