Reflected XSS in Singsys Awesome Gallery Plugin
CVE-2025-23748

7.1HIGH

Key Information:

Vendor
WordPress
Vendor
CVE Published:
14 February 2025

Summary

The Singsys Awesome Gallery plugin for WordPress is vulnerable to reflected Cross-site Scripting (XSS) attacks due to improper input validation during web page generation. This vulnerability allows an attacker to inject malicious scripts into web pages viewed by users, potentially enabling them to steal session tokens, redirect users, or execute arbitrary code in the context of the user’s browser. It affects all versions of the plugin up to 1.0, making it critical for users to upgrade to the latest version and implement necessary security measures.

Affected Version(s)

Singsys -Awesome Gallery <= 1.0

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

João Pedro S Alcântara (Kinorth) (Patchstack Alliance)
.