Impact
The vulnerability is an improper neutralization of input during web page generation in the zackdesign NextGen Cooliris Gallery plugin (CWE‑79), allowing stored cross‑site scripting in pages served by WordPress.
Affected Systems
WordPress sites using the NextGen Cooliris Gallery plugin from the initial release through version 0.7 are vulnerable; any installation that has not upgraded past 0.7 is at risk.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while an EPSS score of less than 1% suggests low probability of exploitation; the plugin is not listed in CISA KEV, further reducing the sense of urgency. The likely attack vector involves an attacker inserting malicious script into gallery fields such as titles or descriptions through an authenticated user role, as the flaw is a stored XSS.
OpenCVE Enrichment
EUVD