Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Subhasis Laha Gallerio gallerio allows Reflected XSS.This issue affects Gallerio: from n/a through <= 1.0.1.
Published: 2025-01-23
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Gallerio plugin contains a reflected XSS flaw caused by inadequate neutralization of characters when generating web pages. An attacker can supply crafted input that is echoed back into the browser, enabling the execution of arbitrary JavaScript in the victim’s context. If an end‑user visits a malicious link or submits a crafted form, the attacker can steal session cookies, hijack accounts, or perform phishing attacks. The vulnerability does not give direct code‑execution rights on the server; its impact is confined to the client side but can compromise confidentiality, integrity, and availability of the user session.

Affected Systems

This flaw affects the Gallerio plugin distributed by Subhasis Laha. Any WordPress installation using Gallerio version 1.0.1 or earlier is vulnerable. The product is widely used for image galleries, so the exposure may be broad in sites that rely on the legacy plugin.

Risk and Exploitability

The CVSS score of 7.1 classifies the vulnerability as high severity. The EPSS score of less than 1% indicates a low probability of exploitation in the near term. It is not listed in the KEV catalog. Based on the description, the likely attack vector is remote, achieved by an attacker supplying malicious input through a URL or form that the plugin processes. The flaw does not require local privileges or user interaction beyond visiting a crafted page, making it relatively easy to exploit for a motivated attacker.

Generated by OpenCVE AI on May 2, 2026 at 05:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Gallerio plugin to a version that contains the XSS fix as soon as it is available.
  • If an update is not yet released, disable or remove the plugin from the WordPress installation to eliminate the vulnerable code path.
  • Configure a web application firewall or security plugin to sanitize or block user‑supplied data that targets the Gallerio endpoints, thereby mitigating the risk of script injection.

Generated by OpenCVE AI on May 2, 2026 at 05:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-3298 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Subhasis Laha Gallerio allows Reflected XSS. This issue affects Gallerio: from n/a through 1.0.1.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Subhasis Laha Gallerio allows Reflected XSS. This issue affects Gallerio: from n/a through 1.0.1. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Subhasis Laha Gallerio gallerio allows Reflected XSS.This issue affects Gallerio: from n/a through <= 1.0.1.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Thu, 23 Jan 2025 15:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Subhasis Laha Gallerio allows Reflected XSS. This issue affects Gallerio: from n/a through 1.0.1.
Title WordPress Gallerio plugin <= 1.0.1 - Reflected Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Subhasis Laha Gallerio
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:14.877Z

Reserved: 2025-01-16T11:27:23.452Z

Link: CVE-2025-23629

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2025-01-23T16:15:38.690

Modified: 2026-04-23T15:24:10.853

Link: CVE-2025-23629

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-02T05:45:20Z

Weaknesses