Impact
The flaw is an improper neutralization of user input during web page generation, allowing an attacker to inject arbitrary JavaScript that will execute in the browser of any visitor to a gallery page. Because the payload is stored, the attack remains until the content is removed or the plugin is updated. This can result in session hijacking, defacement, credential theft, or further malware delivery. The weakness is a stored XSS flaw (CWE‑79).
Affected Systems
The vulnerability targets all versions of the WordPress plugin Justified Image Gallery from PluginsPoint up to and including version 1.0. Sites that allow contributors or administrators to add or edit gallery content are at risk.
Risk and Exploitability
The CVSS score is 6.5, indicating moderate severity. The EPSS score is less than 1 percent, signalling a very low likelihood that this vulnerability is being exploited in the wild. The vulnerability is not listed in CISA’s KEV catalog. An attacker would need to place malicious input into gallery metadata fields—typically requiring user‑level content creation rights or a social‑engineering trick—to persist the payload. Once stored, any visitor to the gallery page will trigger the embedded script.
OpenCVE Enrichment
EUVD