Description
Contributor Cross Site Scripting (XSS) in Photonic Gallery & Lightbox for Flickr, SmugMug & Others <= 3.33 versions.
Published: 2026-07-27
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A contributor Cross Site Scripting vulnerability in Photonic Gallery & Lightbox allows an attacker to inject malicious scripts into gallery pages. The flaw is triggered by untrusted input that is either displayed or executed in the browser. Successful exploitation could lead to execution of arbitrary JavaScript in the context of the user’s browser, enabling actions such as theft of session cookies, defacement, credential theft, or delivery of malicious payloads. The weakness is classed as CWE-79, making it a typical reflected or stored XSS flaw.

Affected Systems

The vulnerability affects the WordPress Photonic Gallery & Lightbox for Flickr, SmugMug & Others plugin by Sayontan Sinha, versions 3.33 and earlier. Users running any of these legacy versions should review their installation immediately.

Risk and Exploitability

The CVSS score is 6.5, indicating a medium severity risk. The EPSS score of <1% shows a very low exploitation probability, and the vulnerability is not listed in CISA KEV, suggesting it has not yet been exploited at scale. The likely attack vector is remote, via web-based input or crafted URLs that include malicious script payloads. An attacker could target users who view the affected galleries or an administrator who submits gallery data through the WordPress interface. The risk is elevated if the site allows unauthenticated users to manage or view gallery content.

Generated by OpenCVE AI on August 3, 2026 at 17:25 UTC.

Remediation

Vendor Solution

Update the WordPress Photonic Gallery & Lightbox for Flickr, SmugMug & Others Plugin to the latest available version (at least 3.34).


OpenCVE Recommended Actions

  • Upgrade the Photonic Gallery & Lightbox plugin to version 3.34 or newer to apply the vendor‑supplied fix.
  • If an upgrade cannot be performed immediately, disable the plugin or replace it with an alternative gallery solution until the patch is applied.
  • Apply strict role‑based access controls so that only trusted administrators can create or edit gallery content, limiting the attack surface.
  • Monitor gallery pages for unexpected JavaScript or changes in site behavior that could indicate a successful XSS exploit.

Generated by OpenCVE AI on August 3, 2026 at 17:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
First Time appeared Sayontan Sinha
Sayontan Sinha photonic Gallery & Lightbox For Flickr, Smugmug & Others
Wordpress
Wordpress wordpress
Vendors & Products Sayontan Sinha
Sayontan Sinha photonic Gallery & Lightbox For Flickr, Smugmug & Others
Wordpress
Wordpress wordpress

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 27 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Description Contributor Cross Site Scripting (XSS) in Photonic Gallery & Lightbox for Flickr, SmugMug & Others <= 3.33 versions.
Title WordPress Photonic Gallery & Lightbox for Flickr, SmugMug & Others plugin <= 3.33 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Sayontan Sinha Photonic Gallery & Lightbox For Flickr, Smugmug & Others
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-27T18:15:48.787Z

Reserved: 2026-07-27T09:00:18.436Z

Link: CVE-2026-66434

cve-icon Vulnrichment

Updated: 2026-07-27T18:15:44.161Z

cve-icon NVD

Status : Deferred

Published: 2026-07-27T15:17:11.047

Modified: 2026-07-27T19:17:23.127

Link: CVE-2026-66434

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T17:30:17Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')