Description
The Envira Gallery WordPress plugin before 1.16.1 does not sanitise or escape user-supplied gallery display configuration values before storing them and outputting them in an image tag attribute, allowing users with the Author role and above to inject arbitrary web scripts that execute when any visitor, including an administrator, views a page containing the affected gallery.
Published: 2026-10-07
Score: 6.8 Medium
EPSS: n/a
KEV: No
Impact: Stored XSS that allows arbitrary script execution when a page containing an affected gallery is viewed
Action: Immediate Patch
AI Analysis

Impact

The Envira Gallery WordPress plugin before version 1.16.1 fails to sanitise or escape user‑supplied gallery display configuration values before storing them and later outputting them in an image tag attribute. This flaw enables users with the Author role or higher to inject arbitrary JavaScript that runs in the browser context of any visitor who views a page containing the gallery, including administrators. An attacker can use the injected scripts to steal user credentials, deface the site, redirect traffic, or perform phishing attacks against site visitors.

Affected Systems

All installations of the Envira Gallery plugin with a version older than 1.16.1 are impacted, regardless of the WordPress site version or other plugins. No precise version list is supplied, so any build before the 1.16.1 release is considered vulnerable.

Risk and Exploitability

The EPSS score is not available and the vulnerability is not listed in CISA KEV, but the CVSS score is 6.8. Exploitation requires the attacker to have the Author role or higher to modify the gallery configuration, after which the managed gallery displays the injected script to all site visitors. Once compromised, all users who view the gallery are exposed to the attacker’s chosen payload, making the risk significant for sites with publicly accessible galleries.

Generated by OpenCVE AI on October 7, 2026 at 11:53 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Envira Gallery to version 1.16.1 or later.
  • Revoke or minimize the Author role for users who are not trusted to configure galleries.
  • Review existing gallery configurations for injected scripts and remove or sanitize any malicious code.
  • Consider implementing a security plugin that enforces input sanitisation or blocks cross‑site scripting on outgoing page content.

Generated by OpenCVE AI on October 7, 2026 at 11:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 10:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 07 Oct 2026 08:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79

Wed, 07 Oct 2026 06:30:00 +0000

Type Values Removed Values Added
Description The Envira Gallery WordPress plugin before 1.16.1 does not sanitise or escape user-supplied gallery display configuration values before storing them and outputting them in an image tag attribute, allowing users with the Author role and above to inject arbitrary web scripts that execute when any visitor, including an administrator, views a page containing the affected gallery.
Title Envira Gallery < 1.16.1 - Author+ Stored XSS via Gallery Crop Dimensions
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-10-07T09:56:20.965Z

Reserved: 2026-10-02T06:49:03.594Z

Link: CVE-2026-104653

cve-icon Vulnrichment

Updated: 2026-10-07T09:55:05.713Z

cve-icon NVD

Status : Received

Published: 2026-10-07T07:16:58.060

Modified: 2026-10-07T10:17:27.677

Link: CVE-2026-104653

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T12:00:15Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')