Impact
In the GhozyLab Gallery – Photo Albums Plugin, unescaped user‑supplied input is stored and rendered in gallery pages, allowing an attacker to inject malicious JavaScript. When a victim visits the affected gallery, the script executes in the victim’s browser, enabling cookie theft, session hijacking, or defacement. This stored XSS flaw is classified as CWE‑79 and poses confidentiality, integrity, and availability risks to users of the plugin.
Affected Systems
GhozyLab’s Gallery – Photo Albums Plugin (easy‑media‑gallery) is vulnerable in all releases through version 1.3.170. WordPress sites deploying any of these plugin versions are at risk until the plugin is updated to a later release. No versions beyond 1.3.170 are affected.
Risk and Exploitability
The vulnerability carries a CVSS score of 6.5 and an EPSS score of less than 1 %, indicating moderate severity and a relatively low probability of exploitation. It is not listed in the CISA KEV catalog. Attackers can exploit the flaw by injecting code via the plugin’s administrative or user input fields, after which the script runs for anyone who views the gallery. The exploit requires user interaction to load the page, but once the payload is stored, repeated exposure increases risk.
OpenCVE Enrichment
EUVD