PT-2026-65692 · WordPress · Photoswipe
CVSS v3.1
6.8
Medium
| Vector | AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
PhotoSwipe WordPress plugin versions prior to 4.1.1.2
Description
The plugin uses the
title attribute of author-supplied link markup as a lightbox caption, which is written into the page DOM without escaping. Since the title attribute bypasses the post-content sanitization for users without the unfiltered html capability, an authenticated user with Author-level access can store a JavaScript payload. This payload executes in the browser of any visitor, including administrators, who clicks the link.Recommendations
Update the PhotoSwipe WordPress plugin to version 4.1.1.2 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Photoswipe