Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dkukral Attach Gallery Posts attach-gallery-posts allows Reflected XSS.This issue affects Attach Gallery Posts: from n/a through <= 1.6.
Published: 2025-03-03
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An improper neutralization of input in dkukral's Attach Gallery Posts plugin allows reflected cross-site scripting. The flaw occurs when user-supplied data is placed in a web page without adequate sanitization, enabling an attacker to inject malicious scripts that will execute in the victim’s browser. This can lead to theft of authentication cookies, identity impersonation, or phishing attacks against site users. The vulnerability is a classic input validation weakness, classified as CWE‑79.

Affected Systems

The plugin Attach Gallery Posts for WordPress is affected in all releases from the initial version up to and including 1.6. Administrators should identify whether site owners deploy any of these versions and note that the plugin author dkukral is the only vendor listed. No other components are affected.

Risk and Exploitability

The CVSS score of 7.1 indicates high impact, while the EPSS of less than 1% suggests a low probability of exploitation in the wild. The flaw is not listed in the CISA KEV catalog. The likely attack vector is a crafted request containing malicious payloads that the plugin reflects back into a dynamically generated page, typically via URL parameters or form inputs. While a successful exploit requires user interaction such as visiting a malicious link, it can be amplified by social engineering or compromised sites.

Generated by OpenCVE AI on May 2, 2026 at 04:04 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Attach Gallery Posts to the latest available version if the vendor has released a patch addressing the vulnerability.
  • If no fixed version is available, disable or remove the plugin entirely to eliminate the vulnerable code path.
  • Apply site-wide input sanitization or a content-security-policy header to help mitigate the execution of injected scripts.
  • Follow the vendor’s advisories on future patches and monitor the plugin repository for any new security releases.

Generated by OpenCVE AI on May 2, 2026 at 04:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-5765 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Attach Gallery Posts allows Reflected XSS. This issue affects Attach Gallery Posts: from n/a through 1.6.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Attach Gallery Posts allows Reflected XSS. This issue affects Attach Gallery Posts: from n/a through 1.6. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dkukral Attach Gallery Posts attach-gallery-posts allows Reflected XSS.This issue affects Attach Gallery Posts: from n/a through <= 1.6.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Tue, 04 Mar 2025 03:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 03 Mar 2025 13:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Attach Gallery Posts allows Reflected XSS. This issue affects Attach Gallery Posts: from n/a through 1.6.
Title WordPress Attach Gallery Posts plugin <= 1.6 - Reflected Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:08.731Z

Reserved: 2025-01-16T11:24:23.109Z

Link: CVE-2025-23441

cve-icon Vulnrichment

Updated: 2025-03-03T20:17:27.357Z

cve-icon NVD

Status : Deferred

Published: 2025-03-03T14:15:35.360

Modified: 2026-06-17T08:54:23.737

Link: CVE-2025-23441

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-02T04:15:06Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')