Impact
The Envira Gallery WordPress plugin before version 1.16.1 fails to sanitise or escape user‑supplied gallery display configuration values before storing them and later outputting them in an image tag attribute. This flaw enables users with the Author role or higher to inject arbitrary JavaScript that runs in the browser context of any visitor who views a page containing the gallery, including administrators. An attacker can use the injected scripts to steal user credentials, deface the site, redirect traffic, or perform phishing attacks against site visitors.
Affected Systems
All installations of the Envira Gallery plugin with a version older than 1.16.1 are impacted, regardless of the WordPress site version or other plugins. No precise version list is supplied, so any build before the 1.16.1 release is considered vulnerable.
Risk and Exploitability
The EPSS score is not available and the vulnerability is not listed in CISA KEV, but the CVSS score is 6.8. Exploitation requires the attacker to have the Author role or higher to modify the gallery configuration, after which the managed gallery displays the injected script to all site visitors. Once compromised, all users who view the gallery are exposed to the attacker’s chosen payload, making the risk significant for sites with publicly accessible galleries.
OpenCVE Enrichment