Cross-Site Scripting Vulnerability in Famous - Responsive Image And Video Grid Gallery Plugin by LambertGroup
CVE-2025-27004
6.1MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 8 January 2026
What is CVE-2025-27004?
A Cross-Site Scripting (XSS) vulnerability in the Famous - Responsive Image And Video Grid Gallery plugin allows malicious users to inject arbitrary JavaScript code into web pages that are viewed by other users. This reflection of input may lead to user session hijacking, redirecting users to malicious sites, or executing unwanted actions in the context of the vulnerable site. This vulnerability affects versions of the plugin up to and including 1.4, presenting significant security risks for websites utilizing this plugin.
Affected Version(s)
Famous - Responsive Image And Video Grid Gallery WordPress Plugin <= n/a
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
João Pedro S Alcântara (Kinorth) | Patchstack Bug Bounty Program