Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dan Rossiter Document Gallery document-gallery allows Reflected XSS.This issue affects Document Gallery: from n/a through <= 5.1.0.
Published: 2026-07-13
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper neutralization of input during web page generation in the Dan Rossiter Document Gallery plugin creates a reflected client-side script injection flaw (CWE-79). The likely attack vector is the delivery of a crafted URL or malicious form input that bypasses the plugin's input sanitization and is reflected in a gallery page. In practice, an attacker can inject arbitrary JavaScript that executes in the browser of any visitor who loads the compromised page. The CVSS rating of 7.1 indicates this flaw is of high severity.

Affected Systems

The flaw affects WordPress sites that have the Dan Rossiter Document Gallery plugin installed in versions up to and including 5.1.0. Any site using these plugin versions is susceptible to the reflected XSS flaw.

Risk and Exploitability

The EPSS score of less than 1% indicates a low but non-zero probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The CVSS score of 7.1 signals high severity. The likely attack vector is inferred to involve the attacker supplying malicious input in a URL or form field that the plugin fails to sanitize. Because this is a reflected XSS, its impact is confined to the victim's browser session and does not allow direct system compromise.

Generated by OpenCVE AI on August 1, 2026 at 10:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Document Gallery to a version newer than 5.1.0.
  • Follow CWE-79 remediation guidelines by ensuring proper output encoding for all user-supplied data reflected in gallery pages.
  • Limit the creation and modification of gallery content to trusted administrators or vetted users to reduce exposure to malicious input.

Generated by OpenCVE AI on August 1, 2026 at 10:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Dan Rossiter
Dan Rossiter document Gallery
Wordpress
Wordpress wordpress
Vendors & Products Dan Rossiter
Dan Rossiter document Gallery
Wordpress
Wordpress wordpress

Mon, 13 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dan Rossiter Document Gallery document-gallery allows Reflected XSS.This issue affects Document Gallery: from n/a through <= 5.1.0.
Title WordPress Document Gallery plugin <= 5.1.0 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Dan Rossiter Document Gallery
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-13T14:38:54.274Z

Reserved: 2026-06-25T08:03:50.157Z

Link: CVE-2026-57695

cve-icon Vulnrichment

Updated: 2026-07-13T13:54:40.567Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T10:45:03Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')