Impact
The Mosaic Gallery – Advanced Gallery plugin contains a contributor Cross‑Site Scripting flaw that permits arbitrary JavaScript injection. This vulnerability, classified as CWE‑79, allows an attacker to execute malicious code in the browsers of anyone who views compromised gallery content. The potential consequences—such as session hijacking, defacement, or malware delivery—are not explicitly outlined in the description, so they are inferred based on the nature of XSS.
Affected Systems
WordPress sites utilizing Misbah WP’s Mosaic Gallery – Advanced Gallery plugin, versions 1.2.0 and earlier.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate risk level, and the EPSS score of < 1% suggests a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is user‑generated gallery content that is rendered without proper sanitization, enabling an attacker to embed crafted payloads that execute in the browser of any visitor to the affected galleries. This can be carried out without elevated privileges and affects all users who load the gallery.
OpenCVE Enrichment