Impact
The vulnerability is an improper neutralization of input during web page generation, enabling attackers to perform stored Cross‑Site Scripting in the origincode Video Gallery – Vimeo and YouTube Gallery plugin. Attacker‑supplied scripts are saved by the plugin and served to other users when gallery pages are viewed. This can lead to session hijacking, credential theft, and defacement, affecting the confidentiality, integrity, and availability of the site for all visitors.
Affected Systems
The affected product is the Video Gallery – Vimeo and YouTube Gallery plugin developed by origincode. All releases up to and including version 1.1.7 are impacted; versions prior to the earliest available release are also included.
Risk and Exploitability
The vendor assigns a CVSS score of 6.5, indicating a moderate severity. The EPSS score is below 1 %, suggesting a low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Attackers likely need to inject malicious payloads through administrative interfaces that allow gallery configuration or content entry; once stored, the injected code executes in the browsers of all users who view the affected pages, making this a high‑impact risk for sites that publicly display galleries.
OpenCVE Enrichment
EUVD