Impact
The vulnerability resides in the Image Photo Gallery Final Tiles Grid WordPress plugin prior to 3.6.14. The plugin fails to sanitise several configuration values that can be supplied through its gallery shortcode. These values are later embedded without escaping directly into an inline script block. A user with contributor level access or higher can therefore inject arbitrary JavaScript that executes inside the browser session of everyone who views the post, including administrators previewing pending submissions. This leads to loss of confidentiality, integrity of the site, and potential session hijacking or defacement.
Affected Systems
All installations of the Image Photo Gallery Final Tiles Grid plugin with a version earlier than 3.6.14 are affected. The weakness is exploitable by anyone who can create or edit gallery shortcodes, which includes contributors and higher. The vulnerability does not require ownership of a particular gallery; any gallery that exists on the site can be referenced by the attacker.
Risk and Exploitability
The vulnerability does not have an EPSS score available and is not listed in the CISA KEV catalog, but its impact is high because any contributor can embed malicious code that runs in the context of all users who view the affected page. The likely attack vector is the gallery shortcode supplied by a contributor. An attacker could embed a malicious script that steals cookies or redirects to malicious sites, thereby compromising administrators and other privileged users. The vulnerability remains in effect until the plugin is updated to version 3.6.14 or later.
OpenCVE Enrichment