Cross-site Scripting Vulnerability in Gallery: Hybrid – Advanced Visual Gallery by DivEngine
CVE-2025-23951

6.5MEDIUM

Key Information:

Vendor
WordPress
Vendor
CVE Published:
16 January 2025

Summary

The vulnerability arises from improper neutralization of user input in the Gallery: Hybrid – Advanced Visual Gallery by DivEngine, allowing an attacker to execute malicious scripts in the user's browser. This issue affects all versions from n/a up to 1.4.0.2, resulting in stored XSS that could compromise user data and session integrity. Web applications utilizing this gallery plugin are at risk, emphasizing the need for immediate patching and user awareness.

Affected Version(s)

Gallery: Hybrid – Advanced Visual Gallery <= 1.4.0.2

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

SOPROBRO (Patchstack Alliance)
.