Description
Contributor Cross Site Scripting (XSS) in Mosaic Gallery &#8211; Advanced Gallery <= 1.2.0 versions.
Published: 2026-07-02
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Mosaic Gallery – Advanced Gallery plugin contains a contributor Cross‑Site Scripting flaw that permits arbitrary JavaScript injection. This vulnerability, classified as CWE‑79, allows an attacker to execute malicious code in the browsers of anyone who views compromised gallery content. The potential consequences—such as session hijacking, defacement, or malware delivery—are not explicitly outlined in the description, so they are inferred based on the nature of XSS.

Affected Systems

WordPress sites utilizing Misbah WP’s Mosaic Gallery – Advanced Gallery plugin, versions 1.2.0 and earlier.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate risk level, and the EPSS score of < 1% suggests a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is user‑generated gallery content that is rendered without proper sanitization, enabling an attacker to embed crafted payloads that execute in the browser of any visitor to the affected galleries. This can be carried out without elevated privileges and affects all users who load the gallery.

Generated by OpenCVE AI on July 21, 2026 at 11:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Deploy the latest Mosaic Gallery – Advanced Gallery release that contains the XSS fix.
  • If a newer release is not immediately available, disable or uninstall the vulnerable plugin to remove the risk.
  • Ensure that any user‑generated content inserted into the gallery is sanitized and encoded, and consider adding a Content‑Security‑Policy header to limit script execution.

Generated by OpenCVE AI on July 21, 2026 at 11:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Misbah Wp
Misbah Wp mosaic Gallery &#8211; Advanced Gallery
Wordpress
Wordpress wordpress
Vendors & Products Misbah Wp
Misbah Wp mosaic Gallery &#8211; Advanced Gallery
Wordpress
Wordpress wordpress

Thu, 02 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Description Contributor Cross Site Scripting (XSS) in Mosaic Gallery &#8211; Advanced Gallery <= 1.2.0 versions.
Title WordPress Mosaic Gallery &#8211; Advanced Gallery plugin <= 1.2.0 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Misbah Wp Mosaic Gallery &#8211; Advanced Gallery
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-02T12:01:36.871Z

Reserved: 2026-06-25T08:04:34.980Z

Link: CVE-2026-57755

cve-icon Vulnrichment

Updated: 2026-07-02T12:01:34.100Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T11:30:06Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')