WordPress Plugin Vulnerabilities

Envira Gallery < 1.16.1 - Author+ Stored XSS via Gallery Image ID

Description

The plugin does not sanitise and escape a gallery item identifier before outputting it in an image tag attribute, allowing users with the Author role and above to inject arbitrary web scripts that execute when any visitor, including an administrator, views a page embedding the gallery.

Proof of Concept

Affects Plugins

Fixed in 1.16.1

References

Classification

Type
XSS
CWE

Miscellaneous

Original Researcher
John Ryan Albon
Submitter
John Ryan Albon
Verified
Yes

Timeline

Publicly Published
2026-10-05 (about 2 days ago)
Added
2026-10-05 (about 1 day ago)
Last Updated
2026-10-05 (about 1 day ago)

Other