Impact
The Envira Gallery WordPress plugin does not sanitize a gallery item identifier before placing it in an image tag attribute. An Author, Editor or Administrator can inject arbitrary JavaScript into that identifier, causing the script to run whenever any visitor— including administrators—views a page that embeds the gallery. This allows cookie theft, session hijacking, defacement, or other client‑side compromise. The vulnerability is a classic stored XSS flaw.
Affected Systems
WordPress sites that use the Envira Gallery plugin in any version earlier than 1.16.1. Users with the Author role or higher are required to exploit the flaw, but once injected the payload affects every visitor of the page that displays the gallery.
Risk and Exploitability
The flaw carries a high severity impact due to the wide range of possible client‑side attacks, though no CVSS score is listed. The EPSS score is not available and the vulnerability is not in the CISA KEV catalog, indicating no confirmed active exploitation reports. The attack vector relies on a legitimate user with an Author role creating or editing a gallery, after which any visitor will be impacted. Because the vulnerability is widely deployable on any WordPress site using the affected plugin, the practical risk is considerable.
OpenCVE Enrichment