Impact
Improper neutralization of input during web page generation in the gt3themes Photo Gallery plugin allows attackers to inject malicious scripts that are reflected back to the user, enabling arbitrary JavaScript execution within the context of any site visitor. The weakness is identified as CWE‑79.
Affected Systems
The vulnerability affects the gt3themes Photo Gallery plugin on any WordPress installation that has not upgraded beyond version 2.7.7.26; no other vendors or products are listed as affected in the CNA data.
Risk and Exploitability
The CVSS base score of 7.1 indicates high severity, while an EPSS score of less than 1% suggests a low current probability of exploitation. The flaw is not present in CISA’s KEV catalog. The likely attack vector is a crafted URL or form input that the plugin reflects back without proper encoding; this inference is based on the description that input is not neutralized during page generation. No special privileges are required for exploitation, and the impact manifests as the execution of arbitrary JavaScript on visitors’ browsers.
OpenCVE Enrichment