Cross-Site Scripting Vulnerability in Famous - Responsive Image And Video Grid Gallery Plugin by LambertGroup
CVE-2025-27004

6.1MEDIUM

What is CVE-2025-27004?

A Cross-Site Scripting (XSS) vulnerability in the Famous - Responsive Image And Video Grid Gallery plugin allows malicious users to inject arbitrary JavaScript code into web pages that are viewed by other users. This reflection of input may lead to user session hijacking, redirecting users to malicious sites, or executing unwanted actions in the context of the vulnerable site. This vulnerability affects versions of the plugin up to and including 1.4, presenting significant security risks for websites utilizing this plugin.

Affected Version(s)

Famous - Responsive Image And Video Grid Gallery WordPress Plugin <= n/a

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

João Pedro S Alcântara (Kinorth) | Patchstack Bug Bounty Program
.