Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gb-plugins GB Gallery Slideshow gb-gallery-slideshow allows Reflected XSS.This issue affects GB Gallery Slideshow: from n/a through <= 1.3.
Published: 2025-04-17
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an improper neutralization of input during web page generation, allowing a reflected XSS attack. An attacker can inject arbitrary JavaScript that runs in the context of a legitimate user’s browser, enabling session hijacking, credential theft, defacement, or malicious redirection. The weakness is classified as CWE‑79.

Affected Systems

The issue exists in the GB Gallery Slideshow WordPress plugin, versions up to and including 1.3. Users who have not upgraded beyond 1.3 are vulnerable.

Risk and Exploitability

The CVSS score of 7.1 indicates high potential for exploitation. EPSS is under 1%, showing that the vulnerability is not highly targeted in the wild. It is not listed in CISA KEV, and no active exploitation has been reported. Attackers can trigger the flaw by crafting a URL that includes specially‑encoded payloads, which the plugin fails to sanitize when rendering the slideshow settings page. Because the flaw is reflected, surrounding the victim’s browser context is sufficient, and no privilege escalation is required.

Generated by OpenCVE AI on April 30, 2026 at 22:02 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update GB Gallery Slideshow to version 1.4 or later (or the latest available) to remove the XSS vector.
  • If an upgrade is not immediately possible, temporarily disable the plugin or remove the affected component from the site.
  • Configure a Web Application Firewall or input‑sanitization plugin to block reflected script payloads targeting the plugin’s parameters.

Generated by OpenCVE AI on April 30, 2026 at 22:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-11722 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gb-plugins GB Gallery Slideshow allows Reflected XSS. This issue affects GB Gallery Slideshow: from n/a through 1.3.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gb-plugins GB Gallery Slideshow allows Reflected XSS. This issue affects GB Gallery Slideshow: from n/a through 1.3. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gb-plugins GB Gallery Slideshow gb-gallery-slideshow allows Reflected XSS.This issue affects GB Gallery Slideshow: from n/a through <= 1.3.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Thu, 17 Apr 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Apr 2025 16:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gb-plugins GB Gallery Slideshow allows Reflected XSS. This issue affects GB Gallery Slideshow: from n/a through 1.3.
Title WordPress GB Gallery Slideshow Plugin <= 1.3 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:26.352Z

Reserved: 2025-04-09T11:21:04.030Z

Link: CVE-2025-32649

cve-icon Vulnrichment

Updated: 2025-04-17T18:08:24.537Z

cve-icon NVD

Status : Deferred

Published: 2025-04-17T16:15:49.033

Modified: 2026-04-23T15:29:16.840

Link: CVE-2025-32649

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T22:15:16Z

Weaknesses