Impact
The vulnerability is a contributor‑initiated cross‑site scripting flaw in Gallery PhotoBlocks plugin versions up to 1.3.4. Unsanitized user input permits the injection of malicious JavaScript that executes in the browsers of visitors or administrators who view a gallery. This can lead to the theft of session data, defacement of the site, or the execution of arbitrary client‑side actions. Based on the description, it is inferred that the attack vector involves form inputs or metadata fields associated with the gallery content where user‑supplied data is displayed unescaped.
Affected Systems
WP Chill’s Gallery PhotoBlocks plugin, versions 1.3.4 and earlier, is impacted. The plugin is a WordPress add‑on that manages grid and photo galleries. The fix is to update to version 1.3.5 or later.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no known widespread exploitation. An attacker would still need to inject content through the plugin’s input mechanisms, which is feasible via normal user access to gallery creation or editing interfaces.
OpenCVE Enrichment