Unauthenticated Cross Site Request Forgery in Photo Gallery by Supsystic
CVE-2026-102399
5.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 30 September 2026
What is CVE-2026-102399?
The Photo Gallery plugin by Supsystic, up to version 1.21.0, contains an unauthenticated Cross Site Request Forgery (CSRF) vulnerability. This security flaw allows attackers to execute actions on behalf of users without their consent, potentially leading to administrative changes or data exposure. Successful exploitation could compromise the integrity of the application and its user data. Plugin users are encouraged to update to the latest version to mitigate this risk.
Affected Version(s)
Photo Gallery by Supsystic <= 1.21.0