Impact
The Gallery for Social Photo plugin from GhozyLab has a stored XSS flaw caused by improper neutralization of input during web page generation. An attacker can inject malicious scripts that execute in the browser of any user viewing the affected gallery, potentially leading to session hijacking, credential theft, or defacement of the site. The weakness is classified as CWE‑79.
Affected Systems
The vulnerable product is the GhozyLab Gallery for Social Photo WordPress plugin. All releases from the initial version through 1.0.0.35 are affected.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, and the EPSS score of less than 1% suggests a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Exploitation most likely occurs when a privileged user configures the plugin, after which arbitrary JavaScript is stored and rendered to visitors. Once the malicious payload is executed, attackers can hijack sessions or install persistent client‑side backdoors. The risk is therefore high for sites that use the plugin and allow external data to be displayed without proper sanitization.
OpenCVE Enrichment
EUVD