Cross-Site Scripting Vulnerability in Meow Gallery by Jordy Meow
CVE-2025-47449

5.9MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
7 May 2025

What is CVE-2025-47449?

A Cross-Site Scripting (XSS) vulnerability has been identified in Meow Gallery by Jordy Meow, which can lead to Stored XSS attacks. The flaw allows an attacker to inject malicious scripts into web pages, potentially compromising the data of users who view the compromised pages. The affected versions range from not applicable to 5.2.7, requiring immediate attention to mitigate risks associated with this vulnerability.

Affected Version(s)

Meow Gallery <= 5.2.7

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

R4mbb (Patchstack Alliance)
.