Impact
The vulnerability is an improper neutralization of input during web page generation, allowing a reflected XSS attack. An attacker can inject arbitrary JavaScript that runs in the context of a legitimate user’s browser, enabling session hijacking, credential theft, defacement, or malicious redirection. The weakness is classified as CWE‑79.
Affected Systems
The issue exists in the GB Gallery Slideshow WordPress plugin, versions up to and including 1.3. Users who have not upgraded beyond 1.3 are vulnerable.
Risk and Exploitability
The CVSS score of 7.1 indicates high potential for exploitation. EPSS is under 1%, showing that the vulnerability is not highly targeted in the wild. It is not listed in CISA KEV, and no active exploitation has been reported. Attackers can trigger the flaw by crafting a URL that includes specially‑encoded payloads, which the plugin fails to sanitize when rendering the slideshow settings page. Because the flaw is reflected, surrounding the victim’s browser context is sufficient, and no privilege escalation is required.
OpenCVE Enrichment
EUVD