Impact
The vulnerability in the pey22 T&P Gallery Slider plugin allows stored cross‑site scripting due to improper neutralization of input during web page generation. Malicious content that is submitted through the plugin can be stored and later rendered to other users’ browsers, enabling arbitrary client‑side script execution. This can affect confidentiality, integrity, or availability of the affected site from the client‑side perspective.
Affected Systems
WordPress sites that have installed pey22’s T&P Gallery Slider plugin version 1.2 or earlier are affected. The issue spans all installations that use the default gallery slider functionality until a later, non‑vulnerable release is applied.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity level. EPSS is below 1%, indicating a low but non‑zero probability of exploitation. The vulnerability is not yet listed in CISA’s KEV catalog. Based on the description, the likely attack vector is the plugin’s administrative input interface where an attacker can submit malicious content that is subsequently stored and rendered to other users. The exploitation would require the attacker to have access to the administrative interface or another means to submit data to the plugin.
OpenCVE Enrichment
EUVD