Impact
The WordPress Galleria plugin contains an improper neutralization of input during web page generation, leading to a reflected cross‑site scripting flaw (CWE‑79). An attacker can inject malicious scripts that execute in the browser of any user who views a malformed gallery page, potentially stealing credentials, hijacking sessions, or defacing the site.
Affected Systems
All installations of the WordPress Galleria plugin up through and including version 1.4 are vulnerable. Users running these versions are at risk, whereas versions newer than 1.4 are not listed as affected.
Risk and Exploitability
The vulnerability has a CVSS score of 7.1, indicating moderate‑to‑high severity, while the EPSS score of <1% suggests a low likelihood of exploitation at present. The flaw is not yet listed in the CISA KEV catalog. Based on the description, the likely attack vector is a crafted URL that contains malicious input displayed in the gallery; the exploit requires a user to visit the vulnerable page in their browser.
OpenCVE Enrichment
EUVD