Impact
The vulnerability is an unauthenticated cross‑site scripting flaw that allows an attacker to inject malicious script into the Document Gallery plugin data fields. This flaw permits the attacker to execute arbitrary JavaScript in the browser of any user who views the affected gallery, which can lead to session hijacking, credential theft, or defacement. The weakness is a classic input validation flaw identified as CWE‑79.
Affected Systems
Affected are installations of the Dan Rossiter Document Gallery WordPress plugin with a version of 5.1.1 or older. No other products or versions are listed in the CNA data. The flaw resides in the plugin’s data handling code that does not properly escape user supplied content.
Risk and Exploitability
The CVSS score of 7.1 reflects a high risk for confidentiality, integrity, and availability. EPSS is not available, and the issue is not currently listed in CISA’s KEV catalog. The attack can be performed without authentication, likely through a crafted gallery entry or URL parameter, which means any visitor to the affected site could be impacted. The lack of a current EPSS score does not diminish the severity indicated by the CVSS; however, it suggests no publicly known exploit at the time of this analysis.
OpenCVE Enrichment