Impact
Improper neutralization of user input in the Good Old Gallery plugin allows a reflected XSS flaw that can inject malicious scripts when a user visits a crafted URL. The attacker can exfiltrate sensitive session data or perform browser-based phishing. The weakness is a classic input validation flaw, identified as CWE‑79. The impact spreads to any visitor of the affected site, compromising confidentiality and potentially integrity if internal scripts are altered.
Affected Systems
The vulnerability affects the Good Old Gallery plugin developed by Linus Lundahl, versions up to and including 2.1.2. WordPress sites running these versions are at risk. No other products or later versions are disclosed as affected.
Risk and Exploitability
The CVSS score of 7.1 marks it as high severity, while the EPSS score of less than 1% indicates a lower likelihood of exploitation in the wild. It is not listed in the CISA KEV catalog. The likely attack vector is client‑side; an attacker can embed an attacker‑controlled payload in a URL that the victim clicks or follows, which is reflected back into the page without proper sanitization.
OpenCVE Enrichment
EUVD