Description
The Image Photo Gallery Final Tiles Grid WordPress plugin before 3.6.14 does not sanitise several gallery configuration values that can be overridden through its gallery shortcode before printing them into an inline script block, allowing users with contributor-level access and above to inject arbitrary JavaScript that executes in the session of anyone viewing the post, including an administrator previewing a pending submission. No gallery ownership is required: any gallery that already exists on the site can be referenced.
Published: 2026-10-08
Score: n/a
EPSS: n/a
KEV: No
Impact: Stored Cross‑Site Scripting (execution of arbitrary JavaScript in the context of any user viewing the gallery)
Action: Apply Patch
AI Analysis

Impact

The vulnerability resides in the Image Photo Gallery Final Tiles Grid WordPress plugin prior to 3.6.14. The plugin fails to sanitise several configuration values that can be supplied through its gallery shortcode. These values are later embedded without escaping directly into an inline script block. A user with contributor level access or higher can therefore inject arbitrary JavaScript that executes inside the browser session of everyone who views the post, including administrators previewing pending submissions. This leads to loss of confidentiality, integrity of the site, and potential session hijacking or defacement.

Affected Systems

All installations of the Image Photo Gallery Final Tiles Grid plugin with a version earlier than 3.6.14 are affected. The weakness is exploitable by anyone who can create or edit gallery shortcodes, which includes contributors and higher. The vulnerability does not require ownership of a particular gallery; any gallery that exists on the site can be referenced by the attacker.

Risk and Exploitability

The vulnerability does not have an EPSS score available and is not listed in the CISA KEV catalog, but its impact is high because any contributor can embed malicious code that runs in the context of all users who view the affected page. The likely attack vector is the gallery shortcode supplied by a contributor. An attacker could embed a malicious script that steals cookies or redirects to malicious sites, thereby compromising administrators and other privileged users. The vulnerability remains in effect until the plugin is updated to version 3.6.14 or later.

Generated by OpenCVE AI on October 8, 2026 at 07:29 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Image Photo Gallery Final Tiles Grid plugin to version 3.6.14 or newer
  • If an immediate update is not possible, remove the plugin or disable the gallery shortcode functionality until the patch is applied
  • Restrict contributor role permissions or audit existing contributor users to prevent misuse of the shortcode until remediation

Generated by OpenCVE AI on October 8, 2026 at 07:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79

Thu, 08 Oct 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Image Photo Gallery Final Tiles Grid WordPress plugin before 3.6.14 does not sanitise several gallery configuration values that can be overridden through its gallery shortcode before printing them into an inline script block, allowing users with contributor-level access and above to inject arbitrary JavaScript that executes in the session of anyone viewing the post, including an administrator previewing a pending submission. No gallery ownership is required: any gallery that already exists on the site can be referenced.
Title Image Photo Gallery Final Tiles Grid < 3.6.14 - Contributor+ Stored XSS via Gallery Shortcode Attributes
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-10-08T06:00:05.880Z

Reserved: 2026-10-02T05:40:36.829Z

Link: CVE-2026-104646

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T06:16:39.147

Modified: 2026-10-08T06:16:39.147

Link: CVE-2026-104646

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T07:30:13Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')