Impact
A contributor Cross Site Scripting vulnerability in Photonic Gallery & Lightbox allows an attacker to inject malicious scripts into gallery pages. The flaw is triggered by untrusted input that is either displayed or executed in the browser. Successful exploitation could lead to execution of arbitrary JavaScript in the context of the user’s browser, enabling actions such as theft of session cookies, defacement, credential theft, or delivery of malicious payloads. The weakness is classed as CWE-79, making it a typical reflected or stored XSS flaw.
Affected Systems
The vulnerability affects the WordPress Photonic Gallery & Lightbox for Flickr, SmugMug & Others plugin by Sayontan Sinha, versions 3.33 and earlier. Users running any of these legacy versions should review their installation immediately.
Risk and Exploitability
The CVSS score is 6.5, indicating a medium severity risk. The EPSS score of <1% shows a very low exploitation probability, and the vulnerability is not listed in CISA KEV, suggesting it has not yet been exploited at scale. The likely attack vector is remote, via web-based input or crafted URLs that include malicious script payloads. An attacker could target users who view the affected galleries or an administrator who submits gallery data through the WordPress interface. The risk is elevated if the site allows unauthenticated users to manage or view gallery content.
OpenCVE Enrichment