Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gt3themes Photo Gallery gt3-photo-video-gallery allows Stored XSS.This issue affects Photo Gallery: from n/a through <= 2.7.7.25.
Published: 2025-05-07
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The plugin contains an improper neutralization of input during web page generation that allows an attacker to inject malicious scripts that are stored in the gallery data. When other users retrieve the gallery, the attacker‑crafted script executes in their browsers, potentially stealing session cookies, defacing content, or executing further malware. The weakness is a classic stored XSS (CWE‑79). According to the official description, the flaw can be exploited by inserting malicious code into gallery fields, which is then persisted and served to any visitor who views the affected gallery page.

Affected Systems

The vulnerability affects the gt3themes Photo Gallery (gt3‑photo‑video‑gallery) plugin for WordPress up to and including version 2.7.7.25. All installations using this or earlier versions are susceptible, so administrators need to verify the running version. The plugin is a gallery module that can be enabled on any WordPress site.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate severity, while the EPSS score of < 1% suggests low likelihood of mass exploitation under normal conditions. The vulnerability is not listed in CISA’s KEV catalog, implying no confirmed large‑scale attacks so far. Exploitation requires the attacker to supply malicious input that is stored by the plugin, typically through a gallery creation or editing interface. Once stored, any visitor who views the gallery will have the injected script executed in their browser, providing a broad audience for the attack. Although the risk is moderate, the potential for user‑impact and data theft warrants prompt remediation.

Generated by OpenCVE AI on April 30, 2026 at 13:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update gt3themes Photo Gallery to a version newer than 2.7.7.25 in which the XSS fix is applied.
  • If an update is unavailable, delete all existing galleries, recreate them after sanitizing any user‑supplied fields, and ensure no script tags remain in the stored content.
  • Restrict editing rights for the gallery features to trusted administrators only and review any custom code that may bypass input validation.

Generated by OpenCVE AI on April 30, 2026 at 13:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-13727 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gt3themes Photo Gallery - GT3 Image Gallery & Gutenberg Block Gallery allows Stored XSS. This issue affects Photo Gallery - GT3 Image Gallery & Gutenberg Block Gallery: from n/a through 2.7.7.25.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gt3themes Photo Gallery - GT3 Image Gallery & Gutenberg Block Gallery allows Stored XSS. This issue affects Photo Gallery - GT3 Image Gallery & Gutenberg Block Gallery: from n/a through 2.7.7.25. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gt3themes Photo Gallery gt3-photo-video-gallery allows Stored XSS.This issue affects Photo Gallery: from n/a through <= 2.7.7.25.
Title WordPress Photo Gallery - GT3 Image Gallery & Gutenberg Block Gallery <= 2.7.7.25 - Cross Site Scripting (XSS) Vulnerability WordPress Photo Gallery - GT3 Image Gallery & Gutenberg Block Gallery plugin <= 2.7.7.25 - Cross Site Scripting (XSS) Vulnerability
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Mon, 14 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00039}

epss

{'score': 0.00045}


Wed, 07 May 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 07 May 2025 14:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gt3themes Photo Gallery - GT3 Image Gallery & Gutenberg Block Gallery allows Stored XSS. This issue affects Photo Gallery - GT3 Image Gallery & Gutenberg Block Gallery: from n/a through 2.7.7.25.
Title WordPress Photo Gallery - GT3 Image Gallery & Gutenberg Block Gallery <= 2.7.7.25 - Cross Site Scripting (XSS) Vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:49.507Z

Reserved: 2025-05-07T10:45:37.286Z

Link: CVE-2025-47677

cve-icon Vulnrichment

Updated: 2025-05-07T17:18:41.308Z

cve-icon NVD

Status : Deferred

Published: 2025-05-07T15:16:19.837

Modified: 2026-04-23T15:30:43.820

Link: CVE-2025-47677

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T13:15:37Z

Weaknesses