Impact
The vulnerability is a cross site scripting flaw in the WordPress Photo Gallery plugin versions 2.7.7.29 and earlier. It allows an attacker to embed malicious JavaScript that will execute in the browser of any visitor who loads the affected gallery. This can lead to theft of session cookies, hijacking of user sessions, or other client‑side attacks that compromise user confidentiality and integrity.
Affected Systems
The flaw affects all installations of the gt3themes WordPress Photo Gallery Plugin with version 2.7.7.29 or earlier. Any WordPress site using these versions is at risk and must upgrade to 2.7.7.30 or a later release.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while the EPSS score of less than 1% suggests exploitation is unlikely at this time. The vulnerability is not listed in the CISA KEV catalog. The description does not detail the exact trigger, so it is inferred that successful exploitation would require an attacker to inject malicious code through an input field or URL that the gallery renders, such as a gallery shortcode or settings page that fails to sanitize content.
OpenCVE Enrichment