Cross-Site Scripting Vulnerability in Jordy Meow Gallery Custom Links Plugin
CVE-2025-60104
5.9MEDIUM
What is CVE-2025-60104?
The Jordy Meow Gallery Custom Links plugin contains a vulnerability that allows for stored Cross-Site Scripting (XSS) attacks due to improper input neutralization during web page generation. This vulnerability affects versions from n/a through 2.2.5, enabling attackers to inject malicious scripts that can be stored and executed when users interact with the compromised web page. This poses significant risks to user data and site integrity.
Affected Version(s)
Gallery Custom Links <= 2.2.5