Cross-Site Scripting Vulnerability in Videowhisper Picture Gallery by WordPress
CVE-2025-26581
7.1HIGH
What is CVE-2025-26581?
The Videowhisper Picture Gallery plugin for WordPress is susceptible to a Cross-Site Scripting (XSS) vulnerability due to improper input handling during page generation. This weakness allows attackers to inject malicious scripts that can be executed in the context of the user's browser. As a result, users may be deceived into performing unintended actions or providing sensitive information without their knowledge. The vulnerability affects all versions of the plugin up to 1.6.2, highlighting the importance of prompt updates and robust security measures for web applications.
Affected Version(s)
Picture Gallery <= 1.6.2
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
João Pedro S Alcântara (Kinorth) (Patchstack Alliance)