Cross-site Scripting Vulnerability in NotFound Global Gallery Plugin by WordPress
CVE-2025-22263
7.1HIGH
What is CVE-2025-22263?
The NotFound Global Gallery plugin is susceptible to a Cross-site Scripting (XSS) vulnerability due to improper input neutralization during web page generation. This flaw allows attackers to execute malicious scripts in the context of users visiting affected pages, potentially resulting in unauthorized actions or data theft. This vulnerability impacts all versions of the Global Gallery plugin up to and including version 8.8.0, making it crucial for website owners to update their installations and implement necessary security measures.
Affected Version(s)
Global Gallery <= 8.8.0