Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gubbigubbi Kona Gallery Block kona-instagram-feed-for-gutenberg allows Stored XSS.This issue affects Kona Gallery Block: from n/a through <= 1.7.
Published: 2025-02-07
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Kona Gallery Block plugin of the gubbigubbi family includes an improper neutralization of input during web page generation, allowing attackers to embed malicious scripts that are stored in the database and later served to site visitors. The stored XSS flaw can be leveraged to inject arbitrary client‑side code, potentially leading to defacement, credential theft, or delivery of malware to users who view pages containing the compromised content. The core weakness is a classic web‑input validation issue as identified by CWE‑79.

Affected Systems

This vulnerability applies to any installation of the Kona Gallery Block plugin up through version 1.7. Users running that plugin version on a WordPress site are affected; later versions are not mentioned as vulnerable.

Risk and Exploitability

The CVSS score of 6.5 reflects a medium severity risk, with no current listing in the CISA KEV catalog and an EPSS score of less than 1%, indicating a low probability of exploitation at present. The most likely attack path would involve an attacker successfully inserting malicious content into a place where the plugin stores gallery data, such as a gallery caption or description field, which is then rendered unfiltered in subsequent page views. Because the flaw is stored, once the data is persisted it can affect all visitors who load the affected page. No known mitigation or patch is listed in the supplied data, so the risk remains contingent on whether the plugin is updated or otherwise managed.

Generated by OpenCVE AI on May 1, 2026 at 17:09 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Kona Gallery Block version 1.8 or later, if available
  • If an upgrade is not immediately possible, remove or disable the plugin until a fix is released
  • Apply a site‑wide Content Security Policy that restricts inline scripts and disallows execution of user‑supplied content

Generated by OpenCVE AI on May 1, 2026 at 17:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-4020 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gubbigubbi Kona Gallery Block allows Stored XSS. This issue affects Kona Gallery Block: from n/a through 1.7.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gubbigubbi Kona Gallery Block allows Stored XSS. This issue affects Kona Gallery Block: from n/a through 1.7. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gubbigubbi Kona Gallery Block kona-instagram-feed-for-gutenberg allows Stored XSS.This issue affects Kona Gallery Block: from n/a through <= 1.7.
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Fri, 07 Feb 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 07 Feb 2025 10:15:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gubbigubbi Kona Gallery Block allows Stored XSS. This issue affects Kona Gallery Block: from n/a through 1.7.
Title WordPress Kona Gallery Block plugin <= 1.7 - Stored Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Gubbigubbi Kona Gallery Block
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:34.858Z

Reserved: 2025-02-03T13:34:11.343Z

Link: CVE-2025-25080

cve-icon Vulnrichment

Updated: 2025-02-07T15:00:43.103Z

cve-icon NVD

Status : Deferred

Published: 2025-02-07T10:15:13.440

Modified: 2026-04-23T15:25:32.213

Link: CVE-2025-25080

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T17:15:21Z

Weaknesses