Impact
WordPress Gallery PhotoBlocks versions up to 1.3.3 contain a contributor‑controlled cross‑site scripting flaw. An attacker who can enter content as a contributor can inject malicious scripts that will execute in the browsers of other site visitors. The vulnerability grants the attacker the ability to run arbitrary code within the context of the affected website, potentially compromising user credentials, defacing content, and facilitating further attacks such as cookie theft or session hijacking.
Affected Systems
The affected product is the WP Chill Gallery PhotoBlocks plugin for WordPress, any installation using version 1.3.3 or earlier is vulnerable.
Risk and Exploitability
The CVSS score of 6.5 indicates medium severity. The EPSS score of < 1% suggests a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is via content submitted by users with contributor privileges, as implied by the description. The vulnerability is exploitable without authentication to the site admin and requires only that a contributor role exists and is abusing the injection point.
OpenCVE Enrichment