Description
The Envira Gallery WordPress plugin before 1.16.1 does not sanitise and escape a gallery item identifier before outputting it in an image tag attribute, allowing users with the Author role and above to inject arbitrary web scripts that execute when any visitor, including an administrator, views a page embedding the gallery.
Published: 2026-10-07
Score: 6.8 Medium
EPSS: n/a
KEV: No
Impact: Stored Cross‑Site Scripting
Action: Immediate Patch
AI Analysis

Impact

The Envira Gallery WordPress plugin does not sanitize a gallery item identifier before placing it in an image tag attribute. An Author, Editor or Administrator can inject arbitrary JavaScript into that identifier, causing the script to run whenever any visitor— including administrators—views a page that embeds the gallery. This allows cookie theft, session hijacking, defacement, or other client‑side compromise. The vulnerability is a classic stored XSS flaw.

Affected Systems

WordPress sites that use the Envira Gallery plugin in any version earlier than 1.16.1. Users with the Author role or higher are required to exploit the flaw, but once injected the payload affects every visitor of the page that displays the gallery.

Risk and Exploitability

The flaw carries a high severity impact due to the wide range of possible client‑side attacks, though no CVSS score is listed. The EPSS score is not available and the vulnerability is not in the CISA KEV catalog, indicating no confirmed active exploitation reports. The attack vector relies on a legitimate user with an Author role creating or editing a gallery, after which any visitor will be impacted. Because the vulnerability is widely deployable on any WordPress site using the affected plugin, the practical risk is considerable.

Generated by OpenCVE AI on October 7, 2026 at 07:30 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Envira Gallery WordPress plugin to version 1.16.1 or newer.
  • If an upgrade is not immediately possible, remove or disable the gallery on the affected pages until a patch can be applied.
  • Limit the use of the Author role by restricting who can edit or create galleries, or use a role‑management plugin to enforce stricter permissions.

Generated by OpenCVE AI on October 7, 2026 at 07:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 10:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 07 Oct 2026 08:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79

Wed, 07 Oct 2026 06:30:00 +0000

Type Values Removed Values Added
Description The Envira Gallery WordPress plugin before 1.16.1 does not sanitise and escape a gallery item identifier before outputting it in an image tag attribute, allowing users with the Author role and above to inject arbitrary web scripts that execute when any visitor, including an administrator, views a page embedding the gallery.
Title Envira Gallery < 1.16.1 - Author+ Stored XSS via Gallery Image ID
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-10-07T09:56:12.270Z

Reserved: 2026-10-02T06:47:36.322Z

Link: CVE-2026-104652

cve-icon Vulnrichment

Updated: 2026-10-07T09:55:18.955Z

cve-icon NVD

Status : Received

Published: 2026-10-07T07:16:57.960

Modified: 2026-10-07T10:17:26.560

Link: CVE-2026-104652

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T07:45:14Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')