Impact
The vulnerability is an unauthenticated cross‑site scripting flaw in versions ≤ 6.5.3 of the MaxGalleria plugin for WordPress. It allows an attacker to inject malicious script into pages that display galleries, which will execute in the browsers of any visitor. Such script execution can lead to session hijacking, defacement, or the theft of data from the client side, reflecting the CWE‑79 weakness.
Affected Systems
Affected systems are WordPress sites that use the MaxGalleria plugin from maxfoundry, specifically version 6.5.3 or older. The fix is available in version 6.5.4, which the advisory recommends installing.
Risk and Exploitability
The CVSS score of 7.1 signals high severity, and the flaw is unauthenticated, meaning every visitor to an infected page is potentially exposed. The EPSS score is not listed and the vulnerability is not in CISA KEV, so there is no documented exploitation data yet, but the exposed nature of the attack vector makes it a significant risk for any site displaying galleries.
OpenCVE Enrichment