JavaScript Injection in Meow Gallery WordPress Plugin by Meow Apps
CVE-2026-15386
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 7 August 2026
Badges
What is CVE-2026-15386?
The Meow Gallery plugin for WordPress, prior to version 5.5.2, is susceptible to a JavaScript injection vulnerability. The plugin fails to properly escape the alt text of attachments when generating output for linked galleries. As a result, users with Author roles or higher are able to store a potentially harmful JavaScript payload. This payload executes in the browsers of any visitors, including site administrators, who view posts containing galleries. Websites utilizing affected versions should apply the necessary updates to mitigate this risk.
Affected Version(s)
Meow Gallery 0 < 5.5.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.