Impact
The vulnerability is an Administrator Cross Site Scripting (XSS) flaw in the Supsystic Photo Gallery by Supsystic plugin versions 1.16.3 and earlier. Attackers can inject arbitrary script code that executes within the browser of any administrator who views the compromised gallery entries. This can result in session hijacking, credential theft, or defacement of the site.
Affected Systems
All WordPress installations that use the Supsystic Photo Gallery by Supsystic plugin version 1.16.3 or lower are affected. The plugin is distributed under the Supsystic brand and is compatible with any WordPress site that supports third‑party plugins.
Risk and Exploitability
The CVSS score of 5.9 classifies the vulnerability as moderate severity. The EPSS score of less than 1% indicates a very low likelihood of exploitation in the field, and it is not currently listed in the CISA KEV catalog. Nonetheless, because XSS can compromise administrative sessions, it should be addressed promptly. The attack vector is likely through the plugin’s administrative interface; an authenticated administrator could create or edit gallery items containing malicious payloads that are rendered unsanitized.
OpenCVE Enrichment