WordPress Plugin Vulnerabilities

Gallery PhotoBlocks 1.3.5 - Contributor+ Stored XSS

Description

The plugin does not sanitize and escape one of its gallery settings before outputting it into an HTML attribute, allowing users with Contributor-level access and above to store JavaScript that executes in the browser of anyone who views a page containing the gallery, including administrators.

Proof of Concept

Affects Plugins

References

Classification

Type
XSS
CWE

Miscellaneous

Original Researcher
Andy Urlep
Submitter
Andy Urlep
Verified
Yes

Timeline

Publicly Published
2026-10-08 (about 2 days ago)
Added
2026-10-08 (about 1 day ago)
Last Updated
2026-10-08 (about 1 day ago)

Other