Stored Cross-Site Scripting Vulnerability in WordPress Picture Gallery by WordPress
CVE-2021-47951
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 10 May 2026
Badges
What is CVE-2021-47951?
The Picture Gallery plugin for WordPress, version 1.4.2, is susceptible to a stored cross-site scripting (XSS) vulnerability. This security flaw allows authenticated users to utilize the Edit Content URL field in the Access Control settings to inject malicious JavaScript code. The injected scripts are stored in the database and can be executed whenever the corresponding functionality is accessed. Exploiters leveraging this vulnerability can facilitate session hijacking and steal sensitive user credentials, posing a significant threat to website security.
Affected Version(s)
Picture Gallery 1.4.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved