Description
Unauthenticated Cross Site Scripting (XSS) in MaxGalleria <= 6.5.3 versions.
Published: 2026-10-01
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: Cross-Site Scripting
Action: Apply Patch
AI Analysis

Impact

The vulnerability is an unauthenticated cross‑site scripting flaw in versions ≤ 6.5.3 of the MaxGalleria plugin for WordPress. It allows an attacker to inject malicious script into pages that display galleries, which will execute in the browsers of any visitor. Such script execution can lead to session hijacking, defacement, or the theft of data from the client side, reflecting the CWE‑79 weakness.

Affected Systems

Affected systems are WordPress sites that use the MaxGalleria plugin from maxfoundry, specifically version 6.5.3 or older. The fix is available in version 6.5.4, which the advisory recommends installing.

Risk and Exploitability

The CVSS score of 7.1 signals high severity, and the flaw is unauthenticated, meaning every visitor to an infected page is potentially exposed. The EPSS score is not listed and the vulnerability is not in CISA KEV, so there is no documented exploitation data yet, but the exposed nature of the attack vector makes it a significant risk for any site displaying galleries.

Generated by OpenCVE AI on October 1, 2026 at 15:57 UTC.

Remediation

Vendor Solution

Update the WordPress MaxGalleria plugin to the latest available version (at least 6.5.4).


OpenCVE Recommended Actions

  • Update the MaxGalleria plugin to version 6.5.4 or later.
  • If a patch cannot be applied immediately, temporarily deactivate or uninstall the plugin, or remove gallery elements from public pages until the update is available.
  • Monitor site traffic for unusual script activity or client‑side compromise indicators to detect potential exploitation attempts.

Generated by OpenCVE AI on October 1, 2026 at 15:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 14:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated Cross Site Scripting (XSS) in MaxGalleria <= 6.5.3 versions.
Title WordPress MaxGalleria plugin <= 6.5.3 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-01T16:02:40.819Z

Reserved: 2026-09-24T10:23:19.164Z

Link: CVE-2026-97260

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-01T15:17:37.820

Modified: 2026-10-01T17:17:35.763

Link: CVE-2026-97260

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T16:00:11Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')