Impact
The My Album Gallery plugin for WordPress is vulnerable to a stored cross‑site scripting flaw. An authenticated user with Contributor-level access or higher can inject arbitrary HTML or JavaScript into the "style_css" shortcode attribute. The injected code is stored in the database and rendered whenever the affected page is accessed, allowing the attacker to steal authentication cookies, deface content, or perform phishing operations against all visitors who view the injected page.
Affected Systems
All installations of the My Album Gallery plugin up to and including version 1.0.4 are affected. This includes any WordPress site that has the plugin installed and accepts the "style_css" attribute in shortcodes.
Risk and Exploitability
The CVSS score of 6.4 places the vulnerability in the high‑moderate range, but the EPSS score is below 1 %, indicating a low likelihood of exploitation in the near term. The flaw is not yet listed in the CISA KEV catalog. Because exploitation requires authentication with Contributor or higher privileges, an attacker must first compromise or log into the site, making the attack less trivial but still possible. Once the malicious content is stored, it will affect all users who view the page.
OpenCVE Enrichment