Cross-site Scripting Vulnerability in Gallery: Hybrid – Advanced Visual Gallery by DivEngine
CVE-2025-23951
6.5MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 16 January 2025
What is CVE-2025-23951?
The vulnerability arises from improper neutralization of user input in the Gallery: Hybrid – Advanced Visual Gallery by DivEngine, allowing an attacker to execute malicious scripts in the user's browser. This issue affects all versions from n/a up to 1.4.0.2, resulting in stored XSS that could compromise user data and session integrity. Web applications utilizing this gallery plugin are at risk, emphasizing the need for immediate patching and user awareness.
Affected Version(s)
Gallery: Hybrid – Advanced Visual Gallery <= 1.4.0.2