Impact
The vulnerability is a stored Cross‑Site Scripting flaw (CWE‑79) in the DIVENGINE Gallery: Hybrid – Advanced Visual Gallery plugin. Improper neutralization of input during page generation allows an attacker to inject malicious JavaScript that will execute in the browsers of any user who views the affected gallery, potentially enabling defacement, credential theft, or other client‑side attacks.
Affected Systems
Sites running the DIVENGINE Gallery: Hybrid – Advanced Visual Gallery plugin with versions from initial release through 1.4.0.2 are affected. No other products or vendors are listed.
Risk and Exploitability
The CVSS score is 6.5, reflecting a moderate severity. The EPSS score is less than 1%, indicating a very low probability of exploitation, and the vulnerability is not yet listed in the CISA KEV catalog. The most likely attack vector involves an attacker submitting malicious payloads via any input fields provided by the plugin, which are subsequently stored and rendered to site visitors.
OpenCVE Enrichment
EUVD