Impact
Ays Pro Photo Gallery by Ays contains a DOM‑Based XSS flaw caused by improper neutralization of user input during web page generation. The vulnerability allows an attacker to inject malicious scripts into the client‑side DOM, resulting in arbitrary JavaScript execution in the victim’s browser as they view the affected page.
Affected Systems
All deployments of Ays Photo Gallery by Ays through version 6.3.8 are affected; no minimum version is specified so any installation of the plugin before 6.3.9 is considered vulnerable.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while the EPSS score of less than 1% suggests that exploitation is unlikely to be common at present. The vulnerability is not listed in CISA’s KEV catalog. An attacker can trigger the flaw by luring a user to a crafted link or by embedding malicious payloads into data that is later rendered by the plugin, leading to client‑side script execution confined to the website’s domain and the browsers of users who visit compromised pages.
OpenCVE Enrichment
EUVD