PT-2026-68865 · WordPress · Meow Gallery
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Meow Gallery versions prior to 5.5.2
Description
Insufficient escaping of an attachment's alt text allows users with the Author role or higher to perform a Stored Cross-Site Scripting (XSS) attack. By injecting a JavaScript payload into the alt text, the script executes in the browser of any visitor, including administrators, who views a post containing a linked gallery.
Recommendations
Update Meow Gallery to version 5.5.2 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Meow Gallery