Reflected XSS in Singsys Awesome Gallery Plugin
CVE-2025-23748
7.1HIGH
Summary
The Singsys Awesome Gallery plugin for WordPress is vulnerable to reflected Cross-site Scripting (XSS) attacks due to improper input validation during web page generation. This vulnerability allows an attacker to inject malicious scripts into web pages viewed by users, potentially enabling them to steal session tokens, redirect users, or execute arbitrary code in the context of the user’s browser. It affects all versions of the plugin up to 1.0, making it critical for users to upgrade to the latest version and implement necessary security measures.
Affected Version(s)
Singsys -Awesome Gallery <= 1.0
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
João Pedro S Alcântara (Kinorth) (Patchstack Alliance)