Impact
The vulnerability in gt3themes Photo Gallery enables an attacker to inject malicious scripts that execute when a user views a gallery page. This reflected XSS flaw can allow an attacker to hijack user sessions, deface the site, or exfiltrate sensitive data. The weakness is the lack of proper escaping when user input is reflected in generated HTML, identified as CWE‑79.
Affected Systems
WordPress sites using the gt3-photo-video-gallery plugin in versions up to and including 2.7.7.24 are affected. The plugin is developed by gt3themes under the Photo Gallery product line.
Risk and Exploitability
The CVSS score of 7.1 denotes a medium‑severity vulnerability. The EPSS score of less than 1% suggests that, at the time of assessment, exploitation frequency is very low, and the flaw is not catalogued in CISA's KEV list. Exploitation would typically require the attacker to craft a URL or embed malicious input in gallery parameters that the plugin fails to sanitize before rendering.
OpenCVE Enrichment
EUVD