Description
Unauthenticated Cross Site Scripting (XSS) in Document Gallery <= 5.1.1 versions.
Published: 2026-10-06
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Cross Site Scripting (XSS)
Action: Patch
AI Analysis

Impact

The vulnerability is an unauthenticated cross‑site scripting flaw that allows an attacker to inject malicious script into the Document Gallery plugin data fields. This flaw permits the attacker to execute arbitrary JavaScript in the browser of any user who views the affected gallery, which can lead to session hijacking, credential theft, or defacement. The weakness is a classic input validation flaw identified as CWE‑79.

Affected Systems

Affected are installations of the Dan Rossiter Document Gallery WordPress plugin with a version of 5.1.1 or older. No other products or versions are listed in the CNA data. The flaw resides in the plugin’s data handling code that does not properly escape user supplied content.

Risk and Exploitability

The CVSS score of 7.1 reflects a high risk for confidentiality, integrity, and availability. EPSS is not available, and the issue is not currently listed in CISA’s KEV catalog. The attack can be performed without authentication, likely through a crafted gallery entry or URL parameter, which means any visitor to the affected site could be impacted. The lack of a current EPSS score does not diminish the severity indicated by the CVSS; however, it suggests no publicly known exploit at the time of this analysis.

Generated by OpenCVE AI on October 6, 2026 at 11:14 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Document Gallery to a version newer than 5.1.1.
  • If upgrading is not possible immediately, remove or disable the plugin until a patch is released.
  • Apply a robust Content Security Policy that restricts script execution to trusted sources.
  • Validate and escape all user inputs through security plugins or custom code.

Generated by OpenCVE AI on October 6, 2026 at 11:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 06 Oct 2026 09:00:00 +0000

Type Values Removed Values Added
Description Unauthenticated Cross Site Scripting (XSS) in Document Gallery <= 5.1.1 versions.
Title WordPress Document Gallery plugin <= 5.1.1 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-06T10:31:34.688Z

Reserved: 2026-04-07T10:59:10.176Z

Link: CVE-2026-39781

cve-icon Vulnrichment

Updated: 2026-10-06T10:29:34.179Z

cve-icon NVD

Status : Received

Published: 2026-10-06T09:17:50.793

Modified: 2026-10-06T11:17:25.373

Link: CVE-2026-39781

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T11:15:18Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')